← Back

CVE-2013-0255

nvd nist
Published: Feb 13, 2013Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:L/Au:S/C:N/I:N/A:C
Exploitability: 8.0 / Impact: 6.9
Source: NVD

Description

PostgreSQL 9.2.x before 9.2.3, 9.1.x before 9.1.8, 9.0.x before 9.0.12, 8.4.x before 8.4.16, and 8.3.x before 8.3.23 does not properly declare the enum_recv function in backend/utils/adt/enum.c, which causes it to be invoked with incorrect arguments and allows remote authenticated users to cause a denial of service (server crash) or read sensitive process memory via a crafted SQL command, which triggers an array index error and an out-of-bounds read.

Affected (59)

1 product
Postgresql
Configuration A
23 vulnerable
Vulnerable SoftwareAffected Versions
Postgresql
Version 8.3.10
Version 8.3.11
Version 8.3.12
Version 8.3.13
Version 8.3.14
Version 8.3.15
Version 8.3.16
Version 8.3.17
Version 8.3.18
Version 8.3.19
Version 8.3.1
Version 8.3.20
Version 8.3.21
Version 8.3.22
Version 8.3.2
Version 8.3.3
Version 8.3.4
Version 8.3.5
Version 8.3.6
Version 8.3.7
Version 8.3.8
Version 8.3.9
Version 8.3
Configuration B
16 vulnerable
Vulnerable SoftwareAffected Versions
Postgresql
Version 8.4.10
Version 8.4.11
Version 8.4.12
Version 8.4.13
Version 8.4.14
Version 8.4.15
Version 8.4.1
Version 8.4.2
Version 8.4.3
Version 8.4.4
Version 8.4.5
Version 8.4.6
Version 8.4.7
Version 8.4.8
Version 8.4.9
Version 8.4
Configuration C
12 vulnerable
Vulnerable SoftwareAffected Versions
Postgresql
Version 9.0.10
Version 9.0.11
Version 9.0.1
Version 9.0.2
Version 9.0.3
Version 9.0.4
Version 9.0.5
Version 9.0.6
Version 9.0.7
Version 9.0.8
Version 9.0.9
Version 9.0
Configuration D
8 vulnerable
Vulnerable SoftwareAffected Versions
Postgresql
Version 9.1.1
Version 9.1.2
Version 9.1.3
Version 9.1.4
Version 9.1.5
Version 9.1.6
Version 9.1.7
Version 9.1
Configuration E
3 platform
Running on/withPlatform Versions
Postgresql
Postgresql
Version 9.2.1
Postgresql
Postgresql
Version 9.2.2
Postgresql
Postgresql
Version 9.2

References (42)

Source: secalert@redhat.com
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.