CVE-2013-0255: PostgreSQL
Medium severity, CVSS 6.8. EPSS: 3.6% chance of exploitation in the next 30 days.
PostgreSQL 9.2.x before 9.2.3, 9.1.x before 9.1.8, 9.0.x before 9.0.12, 8.4.x before 8.4.16, and 8.3.x before 8.3.23 does not properly declare the enum_recv function in backend/utils/adt/enum.c, which causes it to be invoked with incorrect arguments and allows remote authenticated users to cause a denial of service (server crash) or read sensitive process memory via a crafted SQL command, which triggers an array index error and an out-of-bounds read.
Affected products
- PostgreSQL PostgreSQL: version 8.3 only; version 8.3.1 only; version 8.3.2 only; version 8.3.3 only; version 8.3.4 only; version 8.3.5 only; …
Published 2013-02-13. Last modified 2026-06-16.