RSA Authentication Manager Multiple Vulnerabilities in PostgreSQL - False Positive
Originally Published: 2015-11-30
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Platform: SuSE Linux
Platform (Other): PostgreSQL
O/S Version:11
CVE Identifier(s)
Article Summary
IAVM Notice Number: 2015-B-0126 Revision Number: 0.0
Executive Summary:
PostgreSQL has addressed multiple vulnerabilities affecting various versions of the PostgreSQL object-relational database system. PostgreSQL is an open source database system. To exploit these vulnerabilities, an attacker would send a malicious request to an affected application.. If successfully exploited, these vulnerabilities would allow an attacker to gain access to sensitive information, and cause a denial of service condition.
Technical Overview:
CVE-2015-5288:
The crypt() function included with the optional pgCrypto extension could be exploited to read a few additional bytes of memory. No working exploit for this issue has been developed.
Vulnerable Applications/Systems and Countermeasures:
N/A
Vulnerable Applications/Systems with Fixes Available:
PostgreSQL prior to 9.4.5
PostgreSQL prior to 9.3.10
PostgreSQL prior to 9.2.14
PostgreSQL prior to 9.1.19
PostgreSQL prior to 9.0.23
Fix Action: Upgrade to non-vulnerable version of PostgreSQL
Upgrade to:
PostgreSQL 9.4.5 or later
PostgreSQL 9.3.10 or later
PostgreSQL 9.2.14 or later
PostgreSQL 9.1.19 or later
PostgreSQL 9.0.23 or later
Link to Advisories
Alert Impact
Not Applicable
Alert Impact Explanation
Disclaimer
Related Articles
OpenSSL Multiple Vulnerabilities in RSA products 613Number of Views Multiple Apache Tomcat Vulnerabilities in RSA Authentication Manager - False Positive 122Number of Views RSA Authentication Manager 8.x Multiple Vulnerabilities in ISC BIND - False Positive 20Number of Views Access Manager - Multiple vulnerabilities reported in Spring Source "spring-core-3.0.3.RELEASE.jar" - False Positives 56Number of Views RSA Authentication Manager 8.2 Multiple Vulnerabilities - False Positive 60Number of Views
Trending Articles
How a Multi-App Entitlement Collector (MAEDC) resolves entitlement relationships with accounts and groups collected by a M… RSA Governance & Lifecycle 8.0 Patch 10 Release Notes RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows User Event Monitor Messages for Cloud Access Service (20601 - 38000) How to test RSA Identity Router (IDR) Secure Connector connectivity to the RSA ID Plus Cloud Access Service
Don't see what you're looking for?