CVE-2015-5289: Canonical Ubuntu Linux
Medium severity, CVSS 6.4. EPSS: 5% chance of exploitation in the next 30 days.
Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (2) jsonb values.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only
- Debian Debian Linux: version 8.0 only; version 9.0 only
- PostgreSQL PostgreSQL: from 9.3.0, before 9.3.10 (fixed in 9.3.10); from 9.4.0, before 9.4.5 (fixed in 9.4.5)
Published 2015-10-26. Last modified 2026-06-17.