Input validation error in PostgreSQL - CVE-2014-0064

 

Input validation error in PostgreSQL - CVE-2014-0064

Published: March 31, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU41876
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-0064
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to read and manipulate data.

Multiple integer overflows in the path_in and other unspecified functions in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact and attack vectors, which trigger a buffer overflow. NOTE: this identifier has been SPLIT due to different affected versions; use CVE-2014-2669 for the hstore vector.


Affected software

PostgreSQL
Amazon Linux AMI
Gentoo Linux

How to mitigate CVE-2014-0064

Install update from vendor's website.


External References

Related Security Bulletins