CVE-2014-2669

NameCVE-2014-2669
DescriptionMultiple integer overflows in contrib/hstore/hstore_io.c in PostgreSQL 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact via vectors related to the (1) hstore_recv, (2) hstore_from_arrays, and (3) hstore_from_array functions in contrib/hstore/hstore_io.c; and the (4) hstoreArrayToPairs function in contrib/hstore/hstore_op.c, which triggers a buffer overflow. NOTE: this issue was SPLIT from CVE-2014-0064 because it has a different set of affected versions.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-2865-1

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
postgresql-8.4sourcesqueeze(not affected)
postgresql-8.4sourcewheezy(not affected)
postgresql-8.4source(unstable)(unfixed)
postgresql-9.1sourcewheezy9.1.12-0wheezy1DSA-2865-1
postgresql-9.1source(unstable)9.1.12-1
postgresql-9.3source(unstable)9.3.3-1

Notes

[wheezy] - postgresql-8.4 <not-affected> (9.x branch only)
[squeeze] - postgresql-8.4 <not-affected> (9.x branch only)

Search for package or bug name: Reporting problems