Startseite ▼ Bookkeeping
Online ▼ Sicherheits
Überprüfungs ▼
Verwaltetes
DNS ▼
Info
Bestellen/Erneuern
FAQ
AUP
Dynamic DNS Clients
Domaine konfigurieren Dyanmic DNS Update Password Netzwerk
Überwachung ▼
Enterprise
Erweiterte
Standard
Gratis Test
FAQ
Preis/Funktionszusammenfassung
Bestellen
Beispiele
Konfigurieren/Status Alarm Profile | |||
Test Kennung: | 1.3.6.1.4.1.25623.1.0.703270 |
Kategorie: | Debian Local Security Checks |
Titel: | Debian Security Advisory DSA 3270-1 (postgresql-9.4 - security update) |
Zusammenfassung: | Several vulnerabilities have been found in PostgreSQL-9.4, a SQL;database system.;;CVE-2015-3165;;(Remote crash);;SSL clients disconnecting just before the authentication timeout;expires can cause the server to crash.;;CVE-2015-3166;;(Information exposure);;The replacement implementation of snprintf() failed to check for;errors reported by the underlying system library calls. The main;case that might be missed is out-of-memory situations. In the worst;case this might lead to information exposure.;;CVE-2015-3167;;(Possible side-channel key exposure);;In contrib/pgcrypto, some cases of decryption with an incorrect key;could report other error message texts. Fix by using a;one-size-fits-all message. |
Beschreibung: | Summary: Several vulnerabilities have been found in PostgreSQL-9.4, a SQL database system. CVE-2015-3165 (Remote crash) SSL clients disconnecting just before the authentication timeout expires can cause the server to crash. CVE-2015-3166 (Information exposure) The replacement implementation of snprintf() failed to check for errors reported by the underlying system library calls. The main case that might be missed is out-of-memory situations. In the worst case this might lead to information exposure. CVE-2015-3167 (Possible side-channel key exposure) In contrib/pgcrypto, some cases of decryption with an incorrect key could report other error message texts. Fix by using a one-size-fits-all message. Affected Software/OS: postgresql-9.4 on Debian Linux Solution: For the stable distribution (jessie), these problems have been fixed in version 9.4.2-0+deb8u1. For the testing distribution (stretch), these problems will be fixed soon. For the unstable distribution (sid), these problems have been fixed in version 9.4.2-1. We recommend that you upgrade your postgresql-9.4 packages. CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Querverweis: |
Common Vulnerability Exposure (CVE) ID: CVE-2015-3165 http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.html BugTraq ID: 74787 http://www.securityfocus.com/bid/74787 Debian Security Information: DSA-3269 (Google Search) http://www.debian.org/security/2015/dsa-3269 Debian Security Information: DSA-3270 (Google Search) http://www.debian.org/security/2015/dsa-3270 https://security.gentoo.org/glsa/201507-20 RedHat Security Advisories: RHSA-2015:1194 http://rhn.redhat.com/errata/RHSA-2015-1194.html RedHat Security Advisories: RHSA-2015:1195 http://rhn.redhat.com/errata/RHSA-2015-1195.html RedHat Security Advisories: RHSA-2015:1196 http://rhn.redhat.com/errata/RHSA-2015-1196.html http://www.ubuntu.com/usn/USN-2621-1 Common Vulnerability Exposure (CVE) ID: CVE-2015-3166 http://ubuntu.com/usn/usn-2621-1 http://www.postgresql.org/about/news/1587/ http://www.postgresql.org/docs/9.0/static/release-9-0-20.html http://www.postgresql.org/docs/9.1/static/release-9-1-16.html http://www.postgresql.org/docs/9.2/static/release-9-2-11.html http://www.postgresql.org/docs/9.3/static/release-9-3-7.html http://www.postgresql.org/docs/9.4/static/release-9-4-2.html Common Vulnerability Exposure (CVE) ID: CVE-2015-3167 |
Copyright | Copyright (c) 2015 Greenbone Networks GmbH http://greenbone.net |
Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |