CVE-2014-8161: Debian Linux

Medium severity, CVSS 4.3. EPSS: 2.5% chance of exploitation in the next 30 days.

PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • PostgreSQL PostgreSQL: before 9.0.19 (fixed in 9.0.19); from 9.1.0, before 9.1.15 (fixed in 9.1.15); from 9.2.0, before 9.2.10 (fixed in 9.2.10); from 9.3.0, before 9.3.6 (fixed in 9.3.6); from 9.4.0, before 9.4.1 (fixed in 9.4.1)

Published 2020-01-27. Last modified 2026-06-17.