PublicDateAtUSN: 2014-02-21 Candidate: CVE-2014-0063 PublicDate: 2014-03-31 14:58:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0063 http://wiki.postgresql.org/wiki/20140220securityrelease https://ubuntu.com/security/notices/USN-2120-1 Description: Multiple stack-based buffer overflows in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via vectors related to an incorrect MAXDATELEN constant and datetime values involving (1) intervals, (2) timestamps, or (3) timezones, a different vulnerability than CVE-2014-0065. Ubuntu-Description: Notes: Bugs: https://bugs.launchpad.net/ubuntu/+source/postgresql-9.3/+bug/1282677 Priority: medium Discovered-by: Daniel Schüssler Assigned-to: CVSS: Patches_postgresql-9.3: upstream_postgresql-9.3: released (9.3.3) lucid_postgresql-9.3: DNE precise_postgresql-9.3: DNE quantal_postgresql-9.3: DNE saucy_postgresql-9.3: DNE trusty_postgresql-9.3: released (9.3.3-1) trusty/esm_postgresql-9.3: released (9.3.3-1) utopic_postgresql-9.3: DNE devel_postgresql-9.3: DNE Patches_postgresql-9.1: upstream_postgresql-9.1: released (9.1.12) lucid_postgresql-9.1: DNE precise_postgresql-9.1: released (9.1.12-0ubuntu0.12.04) quantal_postgresql-9.1: released (9.1.12-0ubuntu0.12.10) saucy_postgresql-9.1: released (9.1.12-0ubuntu0.13.10) trusty_postgresql-9.1: released (9.1.12-1) trusty/esm_postgresql-9.1: DNE (trusty was released [9.1.12-1]) utopic_postgresql-9.1: DNE devel_postgresql-9.1: DNE Patches_postgresql-8.4: upstream_postgresql-8.4: released (8.4.20) lucid_postgresql-8.4: released (8.4.20-0ubuntu010.04) precise_postgresql-8.4: released (8.4.22-0ubuntu0.12.04) quantal_postgresql-8.4: DNE saucy_postgresql-8.4: DNE trusty_postgresql-8.4: DNE trusty/esm_postgresql-8.4: DNE utopic_postgresql-8.4: DNE devel_postgresql-8.4: DNE