PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-152-1 | postgresql-8.4 update |
Debian DSA |
DSA-3155-1 | postgresql-9.1 security update |
EUVD |
EUVD-2014-8002 | PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message. |
Ubuntu USN |
USN-2499-1 | PostgreSQL vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T13:10:51.110Z
Reserved: 2014-10-10T00:00:00
Link: CVE-2014-8161
No data.
Status : Modified
Published: 2020-01-27T16:15:10.063
Modified: 2024-11-21T02:18:41.270
Link: CVE-2014-8161
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN