CVE-2015-3165: Apple Mac OS X Server
Medium severity, CVSS 4.3. EPSS: 8.4% chance of exploitation in the next 30 days.
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence.
Affected products
- Apple Mac OS X Server: version 5.0.2 only
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 14.10 only; version 15.04 only
- Debian Debian Linux: version 7.0 only; version 8.0 only
- PostgreSQL PostgreSQL: up to and including 9.0.19; version 9.1 only; version 9.1.1 only; version 9.1.2 only; version 9.1.3 only; version 9.1.4 only; …
Published 2015-05-28. Last modified 2026-06-17.