Improper System-Call Error Handling in PostgreSQL
CVE-2015-3166
9.8CRITICAL
Key Information:
- Status
- Vendor
- CVE Published:
- 20 November 2019
What is CVE-2015-3166?
The snprintf implementation in PostgreSQL fails to handle system-call errors properly, which can lead to sensitive information exposure or other unintended consequences. This vulnerability allows attackers to exploit unknown vectors, exemplified by scenarios such as out-of-memory errors. Affected versions include various releases prior to the specified patches, emphasizing the urgent need for updates to safeguard against potential data breaches.
Affected Version(s)
PostgreSQL before 9.0.20
PostgreSQL 9.1.x before 9.1.16
PostgreSQL 9.2.x before 9.2.11