← Back

CVE-2014-2669

nvd nist
Published: Mar 31, 2014Modified: May 6, 2026

JSON object

Loading...
6.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Exploitability: 8.0 / Impact: 6.4
Source: NVD

Description

Multiple integer overflows in contrib/hstore/hstore_io.c in PostgreSQL 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact via vectors related to the (1) hstore_recv, (2) hstore_from_arrays, and (3) hstore_from_array functions in contrib/hstore/hstore_io.c; and the (4) hstoreArrayToPairs function in contrib/hstore/hstore_op.c, which triggers a buffer overflow. NOTE: this issue was SPLIT from CVE-2014-0064 because it has a different set of affected versions.

Affected (37)

1 product
Postgresql
Configuration A
37 vulnerable
Vulnerable SoftwareAffected Versions
Postgresql
Version 9.0.10
Version 9.0.11
Version 9.0.12
Version 9.0.13
Version 9.0.14
Version 9.0.15
Version 9.0.1
Version 9.0.2
Version 9.0.3
Version 9.0.4
Version 9.0.5
Version 9.0.6
Version 9.0.7
Version 9.0.8
Version 9.0.9
Version 9.0
Version 9.1.10
Version 9.1.11
Version 9.1.1
Version 9.1.2
Version 9.1.3
Version 9.1.4
Version 9.1.5
Version 9.1.6
Version 9.1.7
Version 9.1.8
Version 9.1.9
Version 9.1
Version 9.2.1
Version 9.2.2
Version 9.2.3
Version 9.2.4
Version 9.2.5
Version 9.2
Version 9.3.1
Version 9.3.2
Version 9.3

Related CWEs

References (16)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.