V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2016-5423
DEB
High

PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 allow remote authenticated u…

CVSS
8.5
High
EPSS
0.03
p87
Published
2016-01-01
Updated
2016-01-01
Description

PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 allow remote authenticated users to cause a denial of service (NULL pointer dereference and server crash), obtain sensitive memory information, or possibly execute arbitrary code via (1) a CASE expression within the test value subexpression of another CASE or (2) inlining of an SQL function that implements the equality operator used for a CASE expression involving values of different types.

Tags · CWE
CWE-476
CWE-822
CWE-94
CAPEC-35
CAPEC-77
CAPEC-129
CAPEC-242
Affected products
I586-libecpg6.7I586-libecpg6.7-develI586-libecpg6.7-devel-staticI586-libpq5.8I586-libpq5.8-develI586-libpq5.8-devel-staticI586-postgresql9.5-contribI586-postgresql9.5-devel-staticI586-postgresql9.5-perlI586-postgresql9.5-pythonI586-postgresql9.5-serverI586-postgresql9.5-tclLibecpg6.7Libecpg6.7-develLibecpg6.7-devel-staticLibpq5.8Libpq5.8-develLibpq5.8-devel-staticPostgresqlPostgresql-9.1
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Timeline
2016-01-01
Published
2016-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.034 · p87
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-35 · CWE-94
└ via CAPEC-35 · CWE-94
└ via CAPEC-35 · CWE-94
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
i586-libecpg6.7Tracked
i586-libecpg6.7-develTracked
i586-libecpg6.7-devel-staticTracked
i586-libpq5.8Tracked
i586-libpq5.8-develTracked
i586-libpq5.8-devel-staticTracked
i586-postgresql9.5-contribTracked
i586-postgresql9.5-devel-staticTracked
i586-postgresql9.5-perlTracked
i586-postgresql9.5-pythonTracked
i586-postgresql9.5-serverTracked
i586-postgresql9.5-tclTracked
libecpg6.7Tracked
libecpg6.7-develTracked
libecpg6.7-devel-staticTracked
libpq5.8Tracked
libpq5.8-develTracked
libpq5.8-devel-staticTracked
postgresqlTracked
postgresql-9.1Tracked
Source databases
DEB
CVE
RED
UBU