CVE-2016-3065

Publication date 11 April 2016

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

9.1 · Critical

Score breakdown

The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows attackers to bypass intended access restrictions and consequently obtain sensitive server memory information or cause a denial of service (server crash) via a crafted bytea value in a BRIN index page.

Read the notes from the security team

Status

Package Ubuntu Release Status
postgresql-8.4 15.10 wily Not in release
14.04 LTS trusty Not in release
12.04 LTS precise
Not affected
postgresql-9.1 15.10 wily Not in release
14.04 LTS trusty Not in release
12.04 LTS precise
Not affected
postgresql-9.3 15.10 wily Not in release
14.04 LTS trusty
Not affected
12.04 LTS precise Not in release
postgresql-9.4 15.10 wily
Not affected
14.04 LTS trusty Not in release
12.04 LTS precise Not in release
postgresql-9.5 15.10 wily Not in release
14.04 LTS trusty Not in release
12.04 LTS precise Not in release

Notes


sbeattie

affects 9.5 only

Severity score breakdown

Parameter Value
Base score 9.1 · Critical
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact None
Availability impact High
Vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H