CVE-2016-0773

Published on: 02/17/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:12 PM UTC

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Certain versions of Ubuntu Linux from Canonical contain the following vulnerability:

PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large Unicode character range in a regular expression.

  • CVE-2016-0773 has been assigned by [email protected] to track the vulnerability - currently rated as HIGH severity.

CVSS3 Score: 7.5 - HIGH

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK LOW NONE NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED NONE NONE HIGH

CVSS2 Score: 5 - MEDIUM

Access
Vector
Access
Complexity
Authentication
NETWORK LOW NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
NONE NONE PARTIAL

CVE References

Description Tags Link
Debian -- Security Information -- DSA-3475-1 postgresql-9.1 www.debian.org
Depreciated Link
text/html
URL Logo DEBIAN DSA-3475
PostgreSQL: Documentation: 9.5: Release 9.5.1 www.postgresql.org
text/html
URL Logo CONFIRM www.postgresql.org/docs/current/static/release-9-5-1.html
[SECURITY] Fedora 22 Update: postgresql-9.4.6-1.fc22 lists.fedoraproject.org
text/html
URL Logo FEDORA FEDORA-2016-b0c2412ab2
CVE-2016-0773 - PostgreSQL Regular Expression Parsing Vulnerability | Puppet puppet.com
text/html
URL Logo CONFIRM puppet.com/security/cve/CVE-2016-0773
[security-announce] SUSE-SU-2016:0539-1: important: Security update for lists.opensuse.org
text/html
URL Logo SUSE SUSE-SU-2016:0539
[security-announce] SUSE-SU-2016:0555-1: important: Security update for lists.opensuse.org
text/html
URL Logo SUSE SUSE-SU-2016:0555
Red Hat Customer Portal web.archive.org
text/html
Inactive LinkNot Archived
URL Logo REDHAT RHSA-2016:1060
PostgreSQL: Multiple vulnerabilities (GLSA 201701-33) — Gentoo security security.gentoo.org
text/html
URL Logo GENTOO GLSA-201701-33
PostgreSQL: 2016-02-11 Security Update Release Vendor Advisory
www.postgresql.org
text/html
URL Logo CONFIRM www.postgresql.org/about/news/1644/
USN-2894-1: PostgreSQL vulnerabilities | Ubuntu www.ubuntu.com
text/html
URL Logo UBUNTU USN-2894-1
[security-announce] openSUSE-SU-2016:0531-1: important: Security update lists.opensuse.org
text/html
URL Logo SUSE openSUSE-SU-2016:0531
PostgreSQL: Documentation: 9.5: Release 9.4.6 www.postgresql.org
text/html
URL Logo CONFIRM www.postgresql.org/docs/current/static/release-9-4-6.html
PostgreSQL Bugs Let Remote Users Deny Service and Let Remote Authenticated Users Gain Elevated Privileges - SecurityTracker www.securitytracker.com
text/html
URL Logo SECTRACK 1035005
PostgreSQL: Documentation: 9.5: Release 9.2.15 www.postgresql.org
text/html
URL Logo CONFIRM www.postgresql.org/docs/current/static/release-9-2-15.html
PostgreSQL: Documentation: 9.5: Release 9.1.20 www.postgresql.org
text/html
URL Logo CONFIRM www.postgresql.org/docs/current/static/release-9-1-20.html
[security-announce] SUSE-SU-2016:0677-1: important: Security update for lists.opensuse.org
text/html
URL Logo SUSE SUSE-SU-2016:0677
Debian -- Security Information -- DSA-3476-1 postgresql-9.4 www.debian.org
Depreciated Link
text/html
URL Logo DEBIAN DSA-3476
PostgreSQL: Documentation: 9.5: Release 9.3.11 www.postgresql.org
text/html
URL Logo CONFIRM www.postgresql.org/docs/current/static/release-9-3-11.html
Oracle Linux Bulletin - January 2016 www.oracle.com
text/html
URL Logo CONFIRM www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
[SECURITY] Fedora 23 Update: postgresql-9.4.6-1.fc23 lists.fedoraproject.org
text/html
URL Logo FEDORA FEDORA-2016-e0a6c9ebc4
PostgreSQL Integer Overflow and Privilege Escalation Vulnerabilities cve.report (archive)
text/html
URL Logo BID 83184
[security-announce] openSUSE-SU-2016:0578-1: important: Security update lists.opensuse.org
text/html
URL Logo SUSE openSUSE-SU-2016:0578
Knowledge Center kc.mcafee.com
text/html
URL Logo CONFIRM kc.mcafee.com/corporate/index?page=content&id=SB10152

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
Operating
System
CanonicalUbuntu Linux12.04AllAllAll
Operating
System
CanonicalUbuntu Linux14.04AllAllAll
Operating
System
CanonicalUbuntu Linux15.10AllAllAll
Operating
System
CanonicalUbuntu Linux12.04AllAllAll
Operating
System
CanonicalUbuntu Linux14.04AllAllAll
Operating
System
CanonicalUbuntu Linux15.10AllAllAll
Operating
System
DebianDebian Linux7.0AllAllAll
Operating
System
DebianDebian Linux8.0AllAllAll
Operating
System
DebianDebian Linux7.0AllAllAll
Operating
System
DebianDebian Linux8.0AllAllAll
ApplicationPostgresqlPostgresql9.2AllAllAll
ApplicationPostgresqlPostgresql9.2.1AllAllAll
ApplicationPostgresqlPostgresql9.2.10AllAllAll
ApplicationPostgresqlPostgresql9.2.11AllAllAll
ApplicationPostgresqlPostgresql9.2.12AllAllAll
ApplicationPostgresqlPostgresql9.2.13AllAllAll
ApplicationPostgresqlPostgresql9.2.14AllAllAll
ApplicationPostgresqlPostgresql9.2.2AllAllAll
ApplicationPostgresqlPostgresql9.2.3AllAllAll
ApplicationPostgresqlPostgresql9.2.4AllAllAll
ApplicationPostgresqlPostgresql9.2.5AllAllAll
ApplicationPostgresqlPostgresql9.2.6AllAllAll
ApplicationPostgresqlPostgresql9.2.7AllAllAll
ApplicationPostgresqlPostgresql9.2.8AllAllAll
ApplicationPostgresqlPostgresql9.2.9AllAllAll
ApplicationPostgresqlPostgresql9.4AllAllAll
ApplicationPostgresqlPostgresql9.4.1AllAllAll
ApplicationPostgresqlPostgresql9.4.2AllAllAll
ApplicationPostgresqlPostgresql9.4.3AllAllAll
ApplicationPostgresqlPostgresql9.4.4AllAllAll
ApplicationPostgresqlPostgresql9.4.5AllAllAll
ApplicationPostgresqlPostgresql9.5AllAllAll
ApplicationPostgresqlPostgresql9.2AllAllAll
ApplicationPostgresqlPostgresql9.2.1AllAllAll
ApplicationPostgresqlPostgresql9.2.10AllAllAll
ApplicationPostgresqlPostgresql9.2.11AllAllAll
ApplicationPostgresqlPostgresql9.2.12AllAllAll
ApplicationPostgresqlPostgresql9.2.13AllAllAll
ApplicationPostgresqlPostgresql9.2.14AllAllAll
ApplicationPostgresqlPostgresql9.2.2AllAllAll
ApplicationPostgresqlPostgresql9.2.3AllAllAll
ApplicationPostgresqlPostgresql9.2.4AllAllAll
ApplicationPostgresqlPostgresql9.2.5AllAllAll
ApplicationPostgresqlPostgresql9.2.6AllAllAll
ApplicationPostgresqlPostgresql9.2.7AllAllAll
ApplicationPostgresqlPostgresql9.2.8AllAllAll
ApplicationPostgresqlPostgresql9.2.9AllAllAll
ApplicationPostgresqlPostgresql9.4AllAllAll
ApplicationPostgresqlPostgresql9.4.1AllAllAll
ApplicationPostgresqlPostgresql9.4.2AllAllAll
ApplicationPostgresqlPostgresql9.4.3AllAllAll
ApplicationPostgresqlPostgresql9.4.4AllAllAll
ApplicationPostgresqlPostgresql9.4.5AllAllAll
ApplicationPostgresqlPostgresql9.5AllAllAll
ApplicationPostgresqlPostgresqlAllAllAllAll
  • cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*:
  • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.10:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.11:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.12:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.13:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.14:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.7:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.8:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.9:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.10:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.11:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.12:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.13:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.14:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.7:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.8:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.9:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*: