Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or disclose a few bytes of server memory.
Priority: MEDIUM
CVSS v3: 8.1
Component: postgresql
Publish Date: Nov 22, 2017
Related ID: --
CVSS v2: High
Modified Date: Nov 22, 2017
Find out more about CVE-2017-15098 from the MITRE-CVE dictionary and NIST NVD
Login may be required to access defects or downloads.
Product Name |
Status |
Defect |
Fixed |
Downloads |
Notes
Requires LTSS - customers must have active LTSS (Long Term Security Shield) Support to receive up-to-date information about vulnerabilities that may affect legacy software. Please contact your Wind River account team or see https://docs.windriver.com/bundle/Support_and_Maintenance_Supplemental_Terms_and_Conditions and https://support2.windriver.com/index.php?page=plc for more information.