CVE-2015-3167

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
20/11/2019
Last modified:
22/11/2019

Description

contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 9.0.20 (excluding)
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 9.1 (including) 9.1.16 (excluding)
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 9.2 (including) 9.2.11 (excluding)
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 9.3 (including) 9.3.7 (excluding)
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 9.4 (including) 9.4.2 (excluding)
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*