7.5

CVE-2015-3167

contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Postgresql ≫ Postgresql Version < 9.0.20
Postgresql ≫ Postgresql Version >= 9.1 < 9.1.16
Postgresql ≫ Postgresql Version >= 9.2 < 9.2.11
Postgresql ≫ Postgresql Version >= 9.3 < 9.3.7
Postgresql ≫ Postgresql Version >= 9.4 < 9.4.2
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.10
Canonical ≫ Ubuntu Linux Version 15.04
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.13% 0.896
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://www.debian.org/security/2015/dsa-3269
Third Party Advisory
http://www.debian.org/security/2015/dsa-3270
Third Party Advisory
http://www.postgresql.org/about/news/1587/
Vendor Advisory
http://www.postgresql.org/docs/9.0/static/release-9-0-20.html
Vendor Advisory
Release Notes
http://www.postgresql.org/docs/9.1/static/release-9-1-16.html
Vendor Advisory
Release Notes
http://www.postgresql.org/docs/9.2/static/release-9-2-11.html
Vendor Advisory
Release Notes
http://www.postgresql.org/docs/9.3/static/release-9-3-7.html
Vendor Advisory
Release Notes
http://www.postgresql.org/docs/9.4/static/release-9-4-2.html
Vendor Advisory
Release Notes
http://ubuntu.com/usn/usn-2621-1
Third Party Advisory