CVE-2013-1900

PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, and 8.4.x before 8.4.17, when using OpenSSL, generates insufficiently random numbers, which might allow remote authenticated users to have an unspecified impact via vectors related to the "contrib/pgcrypto functions."
References
Link Resource
http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html
http://lists.apple.com/archives/security-announce/2013/Sep/msg00004.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101519.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/102806.html
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00007.html
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00008.html
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00011.html
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00012.html
http://rhn.redhat.com/errata/RHSA-2013-1475.html
http://support.apple.com/kb/HT5880
http://support.apple.com/kb/HT5892
http://www.debian.org/security/2013/dsa-2657
http://www.debian.org/security/2013/dsa-2658
http://www.mandriva.com/security/advisories?name=MDVSA-2013:142
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
http://www.postgresql.org/about/news/1456/ Vendor Advisory
http://www.postgresql.org/docs/current/static/release-8-4-17.html
http://www.postgresql.org/docs/current/static/release-9-0-13.html
http://www.postgresql.org/docs/current/static/release-9-1-9.html
http://www.postgresql.org/docs/current/static/release-9-2-4.html
http://www.ubuntu.com/usn/USN-1789-1
http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html
http://lists.apple.com/archives/security-announce/2013/Sep/msg00004.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101519.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/102806.html
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00007.html
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00008.html
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00011.html
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00012.html
http://rhn.redhat.com/errata/RHSA-2013-1475.html
http://support.apple.com/kb/HT5880
http://support.apple.com/kb/HT5892
http://www.debian.org/security/2013/dsa-2657
http://www.debian.org/security/2013/dsa-2658
http://www.mandriva.com/security/advisories?name=MDVSA-2013:142
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
http://www.postgresql.org/about/news/1456/ Vendor Advisory
http://www.postgresql.org/docs/current/static/release-8-4-17.html
http://www.postgresql.org/docs/current/static/release-9-0-13.html
http://www.postgresql.org/docs/current/static/release-9-1-9.html
http://www.postgresql.org/docs/current/static/release-9-2-4.html
http://www.ubuntu.com/usn/USN-1789-1
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:postgresql:postgresql:9.2:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.2.1:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.2.2:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.2.3:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:postgresql:postgresql:9.1:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.1.1:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.1.2:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.1.3:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.1.4:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.1.5:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.1.6:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.1.7:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.1.8:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:postgresql:postgresql:9.0:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.0.1:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.0.2:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.0.3:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.0.4:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.0.5:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.0.6:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.0.7:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.0.8:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.0.9:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.0.10:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.0.11:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.0.12:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:postgresql:postgresql:8.4:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.1:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.2:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.3:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.4:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.5:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.6:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.7:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.8:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.9:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.10:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.11:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.12:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.13:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.14:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.15:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.16:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:8.04:-:lts:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:10.04:-:lts:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*

History

21 Nov 2024, 01:50

Type Values Removed Values Added
References () http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html - () http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html -
References () http://lists.apple.com/archives/security-announce/2013/Sep/msg00004.html - () http://lists.apple.com/archives/security-announce/2013/Sep/msg00004.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101519.html - () http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101519.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2013-April/102806.html - () http://lists.fedoraproject.org/pipermail/package-announce/2013-April/102806.html -
References () http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00007.html - () http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00007.html -
References () http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00008.html - () http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00008.html -
References () http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00011.html - () http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00011.html -
References () http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00012.html - () http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00012.html -
References () http://rhn.redhat.com/errata/RHSA-2013-1475.html - () http://rhn.redhat.com/errata/RHSA-2013-1475.html -
References () http://support.apple.com/kb/HT5880 - () http://support.apple.com/kb/HT5880 -
References () http://support.apple.com/kb/HT5892 - () http://support.apple.com/kb/HT5892 -
References () http://www.debian.org/security/2013/dsa-2657 - () http://www.debian.org/security/2013/dsa-2657 -
References () http://www.debian.org/security/2013/dsa-2658 - () http://www.debian.org/security/2013/dsa-2658 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2013:142 - () http://www.mandriva.com/security/advisories?name=MDVSA-2013:142 -
References () http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html - () http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html -
References () http://www.postgresql.org/about/news/1456/ - Vendor Advisory () http://www.postgresql.org/about/news/1456/ - Vendor Advisory
References () http://www.postgresql.org/docs/current/static/release-8-4-17.html - () http://www.postgresql.org/docs/current/static/release-8-4-17.html -
References () http://www.postgresql.org/docs/current/static/release-9-0-13.html - () http://www.postgresql.org/docs/current/static/release-9-0-13.html -
References () http://www.postgresql.org/docs/current/static/release-9-1-9.html - () http://www.postgresql.org/docs/current/static/release-9-1-9.html -
References () http://www.postgresql.org/docs/current/static/release-9-2-4.html - () http://www.postgresql.org/docs/current/static/release-9-2-4.html -
References () http://www.ubuntu.com/usn/USN-1789-1 - () http://www.ubuntu.com/usn/USN-1789-1 -

Information

Published : 2013-04-04 17:55

Updated : 2024-11-21 01:50


NVD link : CVE-2013-1900

Mitre link : CVE-2013-1900

CVE.ORG link : CVE-2013-1900


JSON object : View

Products Affected

canonical

  • ubuntu_linux

postgresql

  • postgresql
CWE
CWE-189

Numeric Errors