Vulnerability Description
The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows attackers to bypass intended access restrictions and consequently obtain sensitive server memory information or cause a denial of service (server crash) via a crafted bytea value in a BRIN index page.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Postgresql | Postgresql | 9.5 |
Related Weaknesses (CWE)
References
- http://git.postgresql.org/gitweb/?p=postgresql.git%3Ba=commitdiff%3Bh=bf78a6f107
- http://www.postgresql.org/about/news/1656/PatchVendor Advisory
- http://www.postgresql.org/docs/current/static/release-9-5-2.html
- http://www.securitytracker.com/id/1035468
- http://git.postgresql.org/gitweb/?p=postgresql.git%3Ba=commitdiff%3Bh=bf78a6f107
- http://www.postgresql.org/about/news/1656/PatchVendor Advisory
- http://www.postgresql.org/docs/current/static/release-9-5-2.html
- http://www.securitytracker.com/id/1035468
FAQ
What is CVE-2016-3065?
CVE-2016-3065 is a vulnerability with a CVSS score of 9.1 (CRITICAL). The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows attackers to bypass intended access restrictions and consequentl...
How severe is CVE-2016-3065?
CVE-2016-3065 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-3065?
Check the references section above for vendor advisories and patch information. Affected products include: Postgresql Postgresql.