CVE-2015-5289
Title: Postgresql Memory Corruption
Memory Corruption
Proof Of Concept
No public PoC currently indexed for CVE-2015-5289.
CWE Category
CWE-119
Published Date
Oct 26, 2015
Modified Date
Jun 17, 2026
Exploit Status
Not Found
Score
6.4
CVSS v2.0
Exploit Probability (EPSS)
5.05%
Vulnerability Summary
CVE-2015-5289: Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (2) jsonb values.
Impacted Vendors
Reference Links
http://git.postgresql.org/gitweb/?p=postgresql.git%3Ba=commit%3Bh=08fa47c4850cea32c3116665975bca219fbf2fe6
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172316.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169094.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00016.html
http://lists.opensuse.org/opensuse-updates/2015-11/msg00033.html
http://www.debian.org/security/2015/dsa-3374
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
http://www.postgresql.org/about/news/1615/
http://www.postgresql.org/docs/9.3/static/release-9-3-10.html
http://www.postgresql.org/docs/9.4/static/release-9-4-5.html
http://www.securityfocus.com/bid/77048
http://www.securitytracker.com/id/1033775
http://www.ubuntu.com/usn/USN-2772-1
https://security.gentoo.org/glsa/201701-33
http://git.postgresql.org/gitweb/?p=postgresql.git%3Ba=commit%3Bh=08fa47c4850cea32c3116665975bca219fbf2fe6
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172316.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169094.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00016.html
http://lists.opensuse.org/opensuse-updates/2015-11/msg00033.html
http://www.debian.org/security/2015/dsa-3374
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
http://www.postgresql.org/about/news/1615/
http://www.postgresql.org/docs/9.3/static/release-9-3-10.html
http://www.postgresql.org/docs/9.4/static/release-9-4-5.html
http://www.securityfocus.com/bid/77048
http://www.securitytracker.com/id/1033775
http://www.ubuntu.com/usn/USN-2772-1
https://security.gentoo.org/glsa/201701-33
CVSS v2.0
Source Entity
[email protected]
Severity
MEDIUM
6.4
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:L/Au:N/C:P/I:N/A:P
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2015-5289 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:L/Au:N/C:P/I:N/A:P
Affected Stack
No specific products linked.