CVE Vulnerabilities

CVE-2016-5423

NULL Pointer Dereference

Published: Dec 09, 2016 | Modified: Apr 12, 2025
CVSS 3.x
8.3
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
6.5 MODERATE
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V3
8.5 MODERATE
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 allow remote authenticated users to cause a denial of service (NULL pointer dereference and server crash), obtain sensitive memory information, or possibly execute arbitrary code via (1) a CASE expression within the test value subexpression of another CASE or (2) inlining of an SQL function that implements the equality operator used for a CASE expression involving values of different types.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
Debian_linuxDebian8.0 (including)8.0 (including)
Red Hat Enterprise Linux 7RedHatpostgresql-0:9.2.18-1.el7*
Red Hat Satellite 5.7RedHatrh-postgresql95-0:2.2-3.el6*
Red Hat Satellite 5.7RedHatrh-postgresql95-postgresql-0:9.5.7-2.el6*
Red Hat Satellite 5.7RedHatspacewalk-backend-0:2.3.3-53.el6sat*
Red Hat Satellite 5.7RedHatspacewalk-postgresql-server-0:9.5-1.el6sat*
Red Hat Satellite 5.7RedHatspacewalk-setup-postgresql-0:2.3.0-27.el6sat*
Red Hat Satellite 5.7RedHatspacewalk-utils-0:2.3.2-32.el6sat*
Red Hat Satellite 5.7RedHatspacewalk-web-0:2.3.2-35.el6sat*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-postgresql94-postgresql-0:9.4.9-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatpostgresql92-postgresql-0:9.2.18-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-postgresql95-postgresql-0:9.5.4-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSRedHatrh-postgresql94-postgresql-0:9.4.9-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSRedHatpostgresql92-postgresql-0:9.2.18-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSRedHatrh-postgresql95-postgresql-0:9.5.4-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSRedHatrh-postgresql94-postgresql-0:9.4.9-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSRedHatpostgresql92-postgresql-0:9.2.18-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSRedHatrh-postgresql95-postgresql-0:9.5.4-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-postgresql94-postgresql-0:9.4.9-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatpostgresql92-postgresql-0:9.2.18-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-postgresql95-postgresql-0:9.5.4-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSRedHatrh-postgresql94-postgresql-0:9.4.9-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSRedHatpostgresql92-postgresql-0:9.2.18-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSRedHatrh-postgresql95-postgresql-0:9.5.4-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSRedHatrh-postgresql94-postgresql-0:9.4.9-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSRedHatpostgresql92-postgresql-0:9.2.18-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSRedHatrh-postgresql95-postgresql-0:9.5.4-1.el7*
Postgresql-8.4Ubuntuprecise*
Postgresql-9.1Ubuntuprecise*
Postgresql-9.1Ubuntutrusty*
Postgresql-9.1Ubuntuupstream*
Postgresql-9.3Ubuntuesm-infra-legacy/trusty*
Postgresql-9.3Ubuntutrusty*
Postgresql-9.3Ubuntutrusty/esm*
Postgresql-9.3Ubuntuupstream*
Postgresql-9.5Ubuntuesm-infra/xenial*
Postgresql-9.5Ubuntuupstream*
Postgresql-9.5Ubuntuxenial*

Potential Mitigations

References