CVE-2013-0255 is a denial-of-service vulnerability affecting PostgreSQL versions 9.2.x, 9.1.x, 9.0.x, 8.4.x, and 8.3.x prior to their respective patched releases. It stems from an improperly declared enum_recv function, leading to incorrect argument invocation and an out-of-bounds read. This allows remote authenticated users to trigger a server crash or read sensitive process memory via a crafted SQL command. The vulnerability has a CVSS score of 6.8, indicating a high severity with network access, low complexity, and a complete availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.3CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:8.3:*:*:*:*:*:*:* | ||
8.3.1CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:8.3.1:*:*:*:*:*:*:* | ||
8.3.2CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:8.3.2:*:*:*:*:*:*:* | ||
8.3.3CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:8.3.3:*:*:*:*:*:*:* | ||
8.3.4CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:8.3.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.