PostgreSQL CVE-2014-0064 Multiple Remote Buffer Overflow Vulnerabilities
BID:65725
Info
PostgreSQL CVE-2014-0064 Multiple Remote Buffer Overflow Vulnerabilities
| Bugtraq ID: | 65725 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-0064 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2014 12:00AM |
| Updated: | Apr 13 2015 09:29PM |
| Credit: | Heikki Linnakangas and Noah Misch |
| Vulnerable: |
Ubuntu Ubuntu Linux 13.10 Ubuntu Ubuntu Linux 12.10 Ubuntu Ubuntu Linux 12.04 LTS Ubuntu Ubuntu Linux 10.04 LTS S.u.S.E. openSUSE 11.4 Redhat Software Collections for RHEL 0 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server PostgreSQL PostgreSQL 9.0 PostgreSQL PostgreSQL 9.3 PostgreSQL PostgreSQL 9.2 PostgreSQL PostgreSQL 9.1 PostgreSQL PostgreSQL 8.4 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Nixu NameSurfer 7.5.2 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 Juniper Security Threat Response Manager 2012.1 IBM Tivoli Business Service Manager 4.2.1 IBM Tivoli Business Service Manager 4.2 IBM QRadar Security Information and Event Manager 7.0 MR5 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 5 Avaya IP Office Server Edition 9.0 Avaya IP Office Application Server 9.0 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya CMS R17ac.h Avaya CMS R17ac.g Avaya Aura Conferencing 7.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 SP1 Standard Avaya Aura Communication Manager Utility Services 6.3 Avaya Aura Communication Manager Utility Services 6.2.5.0.15 Avaya Aura Communication Manager Utility Services 6.2.4.0.15 Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1.0.9.8 Avaya Aura Communication Manager Utility Services 6.1 SP 6.1.0.9.8 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.2 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.4 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 Apple Mac OS X Server 3.0 Apple Mac OS X Server 2.0 Apple Mac OS X 10.9.5 |
| Not Vulnerable: |
PostgreSQL PostgreSQL 9.3.3 PostgreSQL PostgreSQL 9.2.7 PostgreSQL PostgreSQL 9.1.12 PostgreSQL PostgreSQL 9.0.16 PostgreSQL PostgreSQL 8.4.20 Nixu NameSurfer 7.5.2.1 Juniper Security Threat Response Manager 2012.1R8 Apple Mac OS X Server 3.2.1 Apple Mac OS X Server 4.0 |
Discussion
PostgreSQL CVE-2014-0064 Multiple Remote Buffer Overflow Vulnerabilities
PostgreSQL is prone to multiple remote buffer-overflow vulnerabilities because it fails to adequately bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers can exploit these issues to execute arbitrary code in the context of the affected application. Failed exploit attempts will result in denial-of-service conditions.
Versions prior to PostgreSQL 9.3.3, 9.2.7, 9.1.12, 9.0.16, and 8.4.20 are vulnerable.
PostgreSQL is prone to multiple remote buffer-overflow vulnerabilities because it fails to adequately bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers can exploit these issues to execute arbitrary code in the context of the affected application. Failed exploit attempts will result in denial-of-service conditions.
Versions prior to PostgreSQL 9.3.3, 9.2.7, 9.1.12, 9.0.16, and 8.4.20 are vulnerable.
Exploit / POC
PostgreSQL CVE-2014-0064 Multiple Remote Buffer Overflow Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
PostgreSQL CVE-2014-0064 Multiple Remote Buffer Overflow Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
-
Mandriva lib64ecpg9.2_6-9.2.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64pq9.2_5-9.2.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql9.2-9.2.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql9.2-contrib-9.2.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql9.2-devel-9.2.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql9.2-docs-9.2.7-1.mbs1.noarch.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql9.2-pl-9.2.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql9.2-plperl-9.2.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql9.2-plpgsql-9.2.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql9.2-plpython-9.2.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql9.2-pltcl-9.2.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql9.2-server-9.2.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
PostgreSQL CVE-2014-0064 Multiple Remote Buffer Overflow Vulnerabilities
References:
References:
- postgresql security update (RHSA-2014-0249) (Avaya)
- About the security content of OS X Server v4.0 (Apple)
- Bug 1065230 - (CVE-2014-0064) CVE-2014-0064 postgresql: integer overflows leadin (Red Hat Bugzilla)
- IBM QRadar Security Information and Event Manager 7.0 MR5 contains multiple vuln (IBM)
- Juniper Secure Analytics (JSA)/Security Threat Response Manager (STRM): Multiple (Juniper)
- PostgreSQL Homepage (PostgreSQL)
- Predict integer overflow to avoid buffer overruns. (nmisch)
- postgresql84 and postgresql security update (RHSA-2014-0211) (Avaya)
- Security Vulnerabilities reported in Tivoli Business Service Manager (ibm)