ISOMAN

CVE

CVE-2015-3167

contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.

Severity
HIGH
CVSS
7.5
Published
Modified

Linked Releases

References

  1. http://ubuntu.com/usn/usn-2621-1
  2. http://www.debian.org/security/2015/dsa-3269
  3. http://www.debian.org/security/2015/dsa-3270
  4. http://www.postgresql.org/about/news/1587/
  5. http://www.postgresql.org/docs/9.0/static/release-9-0-20.html
  6. http://www.postgresql.org/docs/9.1/static/release-9-1-16.html
  7. http://www.postgresql.org/docs/9.2/static/release-9-2-11.html
  8. http://www.postgresql.org/docs/9.3/static/release-9-3-7.html
  9. http://www.postgresql.org/docs/9.4/static/release-9-4-2.html
  10. http://ubuntu.com/usn/usn-2621-1
  11. http://www.debian.org/security/2015/dsa-3269
  12. http://www.debian.org/security/2015/dsa-3270
  13. http://www.postgresql.org/about/news/1587/
  14. http://www.postgresql.org/docs/9.0/static/release-9-0-20.html
  15. http://www.postgresql.org/docs/9.1/static/release-9-1-16.html
  16. http://www.postgresql.org/docs/9.2/static/release-9-2-11.html
  17. http://www.postgresql.org/docs/9.3/static/release-9-3-7.html
  18. http://www.postgresql.org/docs/9.4/static/release-9-4-2.html