CVE Vulnerabilities

CVE-2014-2669

Published: Mar 31, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
6.5 IMPORTANT
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple integer overflows in contrib/hstore/hstore_io.c in PostgreSQL 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact via vectors related to the (1) hstore_recv, (2) hstore_from_arrays, and (3) hstore_from_array functions in contrib/hstore/hstore_io.c; and the (4) hstoreArrayToPairs function in contrib/hstore/hstore_op.c, which triggers a buffer overflow. NOTE: this issue was SPLIT from CVE-2014-0064 because it has a different set of affected versions.

Affected Software

NameVendorStart VersionEnd Version
PostgresqlPostgresql9.0 (including)9.0 (including)
PostgresqlPostgresql9.0.1 (including)9.0.1 (including)
PostgresqlPostgresql9.0.2 (including)9.0.2 (including)
PostgresqlPostgresql9.0.3 (including)9.0.3 (including)
PostgresqlPostgresql9.0.4 (including)9.0.4 (including)
PostgresqlPostgresql9.0.5 (including)9.0.5 (including)
PostgresqlPostgresql9.0.6 (including)9.0.6 (including)
PostgresqlPostgresql9.0.7 (including)9.0.7 (including)
PostgresqlPostgresql9.0.8 (including)9.0.8 (including)
PostgresqlPostgresql9.0.9 (including)9.0.9 (including)
PostgresqlPostgresql9.0.10 (including)9.0.10 (including)
PostgresqlPostgresql9.0.11 (including)9.0.11 (including)
PostgresqlPostgresql9.0.12 (including)9.0.12 (including)
PostgresqlPostgresql9.0.13 (including)9.0.13 (including)
PostgresqlPostgresql9.0.14 (including)9.0.14 (including)
PostgresqlPostgresql9.0.15 (including)9.0.15 (including)
PostgresqlPostgresql9.1 (including)9.1 (including)
PostgresqlPostgresql9.1.1 (including)9.1.1 (including)
PostgresqlPostgresql9.1.2 (including)9.1.2 (including)
PostgresqlPostgresql9.1.3 (including)9.1.3 (including)
PostgresqlPostgresql9.1.4 (including)9.1.4 (including)
PostgresqlPostgresql9.1.5 (including)9.1.5 (including)
PostgresqlPostgresql9.1.6 (including)9.1.6 (including)
PostgresqlPostgresql9.1.7 (including)9.1.7 (including)
PostgresqlPostgresql9.1.8 (including)9.1.8 (including)
PostgresqlPostgresql9.1.9 (including)9.1.9 (including)
PostgresqlPostgresql9.1.10 (including)9.1.10 (including)
PostgresqlPostgresql9.1.11 (including)9.1.11 (including)
PostgresqlPostgresql9.2 (including)9.2 (including)
PostgresqlPostgresql9.2.1 (including)9.2.1 (including)
PostgresqlPostgresql9.2.2 (including)9.2.2 (including)
PostgresqlPostgresql9.2.3 (including)9.2.3 (including)
PostgresqlPostgresql9.2.4 (including)9.2.4 (including)
PostgresqlPostgresql9.2.5 (including)9.2.5 (including)
PostgresqlPostgresql9.3 (including)9.3 (including)
PostgresqlPostgresql9.3.1 (including)9.3.1 (including)
PostgresqlPostgresql9.3.2 (including)9.3.2 (including)
CloudForms Management Engine 5.xRedHatcfme-0:5.2.3.2-1.el6cf*
CloudForms Management Engine 5.xRedHatpostgresql92-postgresql-0:9.2.7-1.1.el6*
CloudForms Management Engine 5.xRedHatprince-0:9.0r2-4.el6cf*
CloudForms Management Engine 5.xRedHatruby193-rubygem-actionpack-1:3.2.13-6.el6cf*
Red Hat Software Collections for RHEL-6RedHatpostgresql92-postgresql-0:9.2.7-1.1.el6*
Postgresql-8.4Ubuntulucid*
Postgresql-8.4Ubuntuprecise*
Postgresql-8.4Ubuntuupstream*
Postgresql-9.1Ubuntuprecise*
Postgresql-9.1Ubuntuquantal*
Postgresql-9.1Ubuntusaucy*
Postgresql-9.1Ubuntutrusty*
Postgresql-9.1Ubuntuupstream*
Postgresql-9.3Ubuntuupstream*

References