VYPR

rpm package

suse/postgresql94&distro=SUSE Manager 2.1

pkg:rpm/suse/postgresql94&distro=SUSE%20Manager%202.1

Vulnerabilities (4)

  • CVE-2016-5424HigDec 9, 2016
    affected < 9.4.9-0.19.1fixed 9.4.9-0.19.1

    PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users with the CREATEDB or CREATEROLE role to gain superuser privileges via a (1) " (double quote), (2) \ (backslash), (3) carriage retu

  • CVE-2016-5423HigDec 9, 2016
    affected < 9.4.9-0.19.1fixed 9.4.9-0.19.1

    PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 allow remote authenticated users to cause a denial of service (NULL pointer dereference and server crash), obtain sensitive memory information, or possibly execute arbit

  • CVE-2015-5289Oct 26, 2015
    affected < 9.4.5-0.8.3fixed 9.4.5-0.8.3

    Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (2) jsonb values.

  • CVE-2015-5288Oct 26, 2015
    affected < 9.4.5-0.8.3fixed 9.4.5-0.8.3

    The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9.1.x before 9.1.19, 9.2.x before 9.2.14, 9.3.x before 9.3.10, and 9.4.x before 9.4.5 allows attackers to cause a denial of service (server crash) or read arbitrary server memory via a "too-short" salt.