PostgreSQL CVE-2014-0063 Remote Stack Buffer Overflow Vulnerability
BID:65719
Info
PostgreSQL CVE-2014-0063 Remote Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 65719 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-0063 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2014 12:00AM |
| Updated: | Apr 13 2015 09:00PM |
| Credit: | Daniel Schuessler |
| Vulnerable: |
Ubuntu Ubuntu Linux 10.04 LTS SuSE openSUSE 11.4 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server PostgreSQL PostgreSQL 9.0 PostgreSQL PostgreSQL 9.2 PostgreSQL PostgreSQL 9.1 PostgreSQL PostgreSQL 8.4 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 IBM Tivoli Business Service Manager 4.2.1 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 5 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 SP1 Standard Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 |
| Not Vulnerable: | |
Discussion
PostgreSQL CVE-2014-0063 Remote Stack Buffer Overflow Vulnerability
PostgreSQL is prone to a remote stack-based buffer-overflow vulnerability because it fails to adequately bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will result in denial-of-service conditions.
Versions prior to PostgreSQL 9.3.3, 9.2.7, 9.1.12, 9.0.16, and 8.4.20 are vulnerable.
PostgreSQL is prone to a remote stack-based buffer-overflow vulnerability because it fails to adequately bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will result in denial-of-service conditions.
Versions prior to PostgreSQL 9.3.3, 9.2.7, 9.1.12, 9.0.16, and 8.4.20 are vulnerable.
Exploit / POC
PostgreSQL CVE-2014-0063 Remote Stack Buffer Overflow Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
PostgreSQL CVE-2014-0063 Remote Stack Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
PostgreSQL CVE-2014-0063 Remote Stack Buffer Overflow Vulnerability
References:
References:
- PostgreSQL Homepage (PostgreSQL)