CVE-2017-15098
Public on 2017-11-22
Modified on 2017-12-06
Description
Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or disclose a few bytes of server memory.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 1 | postgresql92 | 2017-12-05 | ALAS-2017-931 | Fixed |
Amazon Linux 1 | postgresql93 | 2017-12-05 | ALAS-2017-931 | Fixed |
Amazon Linux 1 | postgresql94 | 2017-12-05 | ALAS-2017-931 | Fixed |
Amazon Linux 1 | postgresql95 | 2017-12-05 | ALAS-2017-930 | Fixed |
Amazon Linux 1 | postgresql96 | 2017-12-05 | ALAS-2017-930 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 7.1 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H |
NVD | CVSSv2 | 5.5 | AV:N/AC:L/Au:S/C:P/I:N/A:P |
NVD | CVSSv3 | 8.1 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |