CVE-2014-8161
Summary
| CVE | CVE-2014-8161 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-27 16:15:00 UTC |
| Updated | 2020-01-31 15:24:00 UTC |
| Description | PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message. |
Risk And Classification
Problem Types: CWE-209
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Application | Postgresql | Postgresql | All | All | All | All |
| Application | Postgresql | Postgresql | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-3155-1 postgresql-9.1 | CONFIRM | www.debian.org | Third Party Advisory |
| PostgreSQL: Documentation: 9.4: Release 9.0.19 | CONFIRM | www.postgresql.org | Release Notes, Vendor Advisory |
| PostgreSQL: PostgreSQL 9.4.1, 9.3.6, 9.2.10, 9.1.15 & 9.0.19 Released | CONFIRM | www.postgresql.org | Vendor Advisory |
| PostgreSQL: Documentation: 9.4: Release 9.1.15 | CONFIRM | www.postgresql.org | Release Notes, Vendor Advisory |
| PostgreSQL: Documentation: 9.4: Release 9.2.10 | CONFIRM | www.postgresql.org | Release Notes, Vendor Advisory |
| PostgreSQL: Documentation: 9.4: Release 9.4.1 | CONFIRM | www.postgresql.org | Release Notes, Vendor Advisory |
| PostgreSQL: Documentation: 9.4: Release 9.3.6 | CONFIRM | www.postgresql.org | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.