CVE Vulnerabilities

CVE-2016-5423

NULL Pointer Dereference

Published: Dec 09, 2016 | Modified: Jan 05, 2018
CVSS 3.x
8.3
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
6.5 MODERATE
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V3
8.5 MODERATE
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Ubuntu
MEDIUM

PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 allow remote authenticated users to cause a denial of service (NULL pointer dereference and server crash), obtain sensitive memory information, or possibly execute arbitrary code via (1) a CASE expression within the test value subexpression of another CASE or (2) inlining of an SQL function that implements the equality operator used for a CASE expression involving values of different types.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Debian_linux Debian 8.0 (including) 8.0 (including)
Red Hat Enterprise Linux 7 RedHat postgresql-0:9.2.18-1.el7 *
Red Hat Satellite 5.7 RedHat rh-postgresql95-0:2.2-3.el6 *
Red Hat Satellite 5.7 RedHat rh-postgresql95-postgresql-0:9.5.7-2.el6 *
Red Hat Satellite 5.7 RedHat spacewalk-backend-0:2.3.3-53.el6sat *
Red Hat Satellite 5.7 RedHat spacewalk-postgresql-server-0:9.5-1.el6sat *
Red Hat Satellite 5.7 RedHat spacewalk-setup-postgresql-0:2.3.0-27.el6sat *
Red Hat Satellite 5.7 RedHat spacewalk-utils-0:2.3.2-32.el6sat *
Red Hat Satellite 5.7 RedHat spacewalk-web-0:2.3.2-35.el6sat *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat rh-postgresql94-postgresql-0:9.4.9-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat postgresql92-postgresql-0:9.2.18-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat rh-postgresql95-postgresql-0:9.5.4-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS RedHat rh-postgresql94-postgresql-0:9.4.9-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS RedHat postgresql92-postgresql-0:9.2.18-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS RedHat rh-postgresql95-postgresql-0:9.5.4-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS RedHat rh-postgresql94-postgresql-0:9.4.9-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS RedHat postgresql92-postgresql-0:9.2.18-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS RedHat rh-postgresql95-postgresql-0:9.5.4-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-postgresql94-postgresql-0:9.4.9-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat postgresql92-postgresql-0:9.2.18-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-postgresql95-postgresql-0:9.5.4-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS RedHat rh-postgresql94-postgresql-0:9.4.9-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS RedHat postgresql92-postgresql-0:9.2.18-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS RedHat rh-postgresql95-postgresql-0:9.5.4-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS RedHat rh-postgresql94-postgresql-0:9.4.9-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS RedHat postgresql92-postgresql-0:9.2.18-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS RedHat rh-postgresql95-postgresql-0:9.5.4-1.el7 *
Postgresql-8.4 Ubuntu precise *
Postgresql-9.1 Ubuntu precise *
Postgresql-9.1 Ubuntu trusty *
Postgresql-9.1 Ubuntu upstream *
Postgresql-9.3 Ubuntu trusty *
Postgresql-9.3 Ubuntu upstream *
Postgresql-9.5 Ubuntu upstream *
Postgresql-9.5 Ubuntu xenial *

Potential Mitigations

References