RSA Authentication Manager Multiple Vulnerabilities in PostgreSQL - False Positive
Originally Published: 2015-11-30
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Platform: SuSE Linux
Platform (Other): PostgreSQL
O/S Version:11
CVE Identifier(s)
Article Summary
IAVM Notice Number: 2015-B-0126 Revision Number: 0.0
Executive Summary:
PostgreSQL has addressed multiple vulnerabilities affecting various versions of the PostgreSQL object-relational database system. PostgreSQL is an open source database system. To exploit these vulnerabilities, an attacker would send a malicious request to an affected application.. If successfully exploited, these vulnerabilities would allow an attacker to gain access to sensitive information, and cause a denial of service condition.
Technical Overview:
CVE-2015-5288:
The crypt() function included with the optional pgCrypto extension could be exploited to read a few additional bytes of memory. No working exploit for this issue has been developed.
Vulnerable Applications/Systems and Countermeasures:
N/A
Vulnerable Applications/Systems with Fixes Available:
PostgreSQL prior to 9.4.5
PostgreSQL prior to 9.3.10
PostgreSQL prior to 9.2.14
PostgreSQL prior to 9.1.19
PostgreSQL prior to 9.0.23
Fix Action: Upgrade to non-vulnerable version of PostgreSQL
Upgrade to:
PostgreSQL 9.4.5 or later
PostgreSQL 9.3.10 or later
PostgreSQL 9.2.14 or later
PostgreSQL 9.1.19 or later
PostgreSQL 9.0.23 or later
Link to Advisories
Alert Impact
Not Applicable
Alert Impact Explanation
Disclaimer
Related Articles
Multiple Apache Tomcat Vulnerabilities in RSA Authentication Manager - False Positive 126Number of Views OpenSSL Multiple Vulnerabilities in RSA products 616Number of Views RSA Authentication Manager 8.2 Multiple Vulnerabilities - False Positive 60Number of Views RSA Authentication Manager 8.x Multiple Vulnerabilities in ISC BIND - False Positive 20Number of Views Access Manager - Multiple vulnerabilities reported in Spring Source "spring-core-3.0.3.RELEASE.jar" - False Positives 56Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows RSA Authentication Manager 8.9 Patches and Hotfixes Readme Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?