CVE-2015-3167
Summary
| CVE | CVE-2015-3167 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-20 21:15:00 UTC |
| Updated | 2019-11-22 15:18:00 UTC |
| Description | contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 12.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 15.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 12.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 15.04 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Postgresql | Postgresql | All | All | All | All |
| Application | Postgresql | Postgresql | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PostgreSQL: Documentation: 9.3: Release 9.3.7 | MISC | www.postgresql.org | Release Notes, Vendor Advisory |
| Debian -- Security Information -- DSA-3269-1 postgresql-9.1 | MISC | www.debian.org | Third Party Advisory |
| Debian -- Security Information -- DSA-3270-1 postgresql-9.4 | MISC | www.debian.org | Third Party Advisory |
| USN-2621-1: PostgreSQL vulnerabilities | Ubuntu | MISC | ubuntu.com | Third Party Advisory |
| PostgreSQL: Documentation: 9.4: Release 9.4.2 | MISC | www.postgresql.org | Release Notes, Vendor Advisory |
| PostgreSQL: Documentation: 9.2: Release 9.2.11 | MISC | www.postgresql.org | Release Notes, Vendor Advisory |
| PostgreSQL: Documentation: 9.0: Release 9.0.20 | MISC | www.postgresql.org | Release Notes, Vendor Advisory |
| PostgreSQL: PostgreSQL 9.4.2, 9.3.7, 9.2.11, 9.1.16, and 9.0.20 released! | MISC | www.postgresql.org | Vendor Advisory |
| PostgreSQL: Documentation: 9.1: Release 9.1.16 | MISC | www.postgresql.org | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.