CVE-2013-1900
Summary
| CVE | CVE-2013-1900 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-04-04 17:55:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, and 8.4.x before 8.4.17, when using OpenSSL, generates insufficiently random numbers, which might allow remote authenticated users to have an unspecified impact via vectors related to the "contrib/pgcrypto functions." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 10.04 | - | lts | All |
| Operating System | Canonical | Ubuntu Linux | 11.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 12.04 | - | lts | All |
| Operating System | Canonical | Ubuntu Linux | 12.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 8.04 | - | lts | All |
| Application | Postgresql | Postgresql | 8.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.10 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.11 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.12 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.13 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.14 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.15 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.16 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.6 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.8 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.9 | All | All | All |
| Application | Postgresql | Postgresql | 9.0 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.1 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.10 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.11 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.12 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.2 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.3 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.4 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.5 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.6 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.7 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.8 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.9 | All | All | All |
| Application | Postgresql | Postgresql | 9.1 | All | All | All |
| Application | Postgresql | Postgresql | 9.1.1 | All | All | All |
| Application | Postgresql | Postgresql | 9.1.2 | All | All | All |
| Application | Postgresql | Postgresql | 9.1.3 | All | All | All |
| Application | Postgresql | Postgresql | 9.1.4 | All | All | All |
| Application | Postgresql | Postgresql | 9.1.5 | All | All | All |
| Application | Postgresql | Postgresql | 9.1.6 | All | All | All |
| Application | Postgresql | Postgresql | 9.1.7 | All | All | All |
| Application | Postgresql | Postgresql | 9.1.8 | All | All | All |
| Application | Postgresql | Postgresql | 9.2 | All | All | All |
| Application | Postgresql | Postgresql | 9.2.1 | All | All | All |
| Application | Postgresql | Postgresql | 9.2.2 | All | All | All |
| Application | Postgresql | Postgresql | 9.2.3 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PostgreSQL: Documentation: 9.3: Release 9.1.9 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | |
| [security-announce] openSUSE-SU-2013:0635-1: important: postgresql: secu | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Debian -- Security Information -- DSA-2658-1 postgresql-9.1 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| APPLE-SA-2013-09-12-1 OS X Mountain Lion v10.8.5 and Security Update 2013-004 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| About the security content of OS X Mountain Lion v10.8.5 and Security Update 2013-004 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| [security-announce] openSUSE-SU-2013:0627-1: important: postgresql91 to | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| About the security content of OS X Server v2.2.2 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| [security-announce] openSUSE-SU-2013:0628-1: important: postgresql92: Va | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [SECURITY] Fedora 17 Update: postgresql-9.1.9-1.fc17 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| [SECURITY] Fedora 19 Update: postgresql-9.2.4-1.fc19 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Debian -- Security Information -- DSA-2657-1 postgresql-8.4 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| PostgreSQL: PostgreSQL 9.2.4, 9.1.9, 9.0.13 and 8.4.17 released | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Vendor Advisory |
| APPLE-SA-2013-09-17-1 OS X Server v2.2.2 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Oracle Critical Patch Update - October 2017 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| PostgreSQL: Documentation: 9.3: Release 8.4.17 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | |
| PostgreSQL: Documentation: 9.3: Release 9.2.4 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | |
| USN-1789-1: PostgreSQL vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| PostgreSQL: Documentation: 9.3: Release 9.0.13 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | |
| [security-announce] SUSE-SU-2013:0633-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Support / Security / Advisories / / MDVSA-2013:142 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.