PostgreSQL Information Leakage Vulnerability (CVE-2015-3166)
PostgreSQL Information Leakage Vulnerability (CVE-2015-3166)
Release date:
Updated on:
Affected Systems:
PostgreSQL 9.4
PostgreSQL 9.3
Description:
Bugtraq id: 74790
CVE (CAN) ID: CVE-2015-3166
PostgreSQL is an advanced object-relational database management system that supports extended SQL standard subsets.
In PostgreSQL 9.3 and 9.4, the snprintf () function does not check errors reported by lower-level databases, which may cause insufficient memory and information leakage.
<* Source: Noah Misch
Link: http://www.securityfocus.com/archive/1/535591
*>
Suggestion:
Vendor patch:
PostgreSQL
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.postgresql.org/about/news/1587/
This article permanently updates the link address: