Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-41862

Опубликовано: 03 мар. 2023
Источник: debian
EPSS Низкий

Описание

In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
postgresql-15fixed15.2-1package
postgresql-13removedpackage
postgresql-13fixed13.10-0+deb11u1bullseyepackage
postgresql-11not-affectedpackage

Примечания

  • https://www.postgresql.org/about/news/postgresql-152-147-1310-1214-and-1119-released-2592/

  • Fixed in 15.2, 14.7, 13.10, 12.14

  • https://git.postgresql.org/gitweb/?p=postgresql.git;a=commitdiff;h=3f7342671341a7a137f2d8b06ab3461cdb0e1d88 (REL_12_14)

  • GSSAPI encryption support introduced in https://git.postgresql.org/gitweb/?p=postgresql.git;a=commitdiff;h=b0b39f72b9904bcb80f97b35837ccff1578aa4b8 (REL_12_BETA1)

EPSS

Процентиль: 40%
0.00181
Низкий

Связанные уязвимости

CVSS3: 3.7
ubuntu
больше 2 лет назад

In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.

CVSS3: 3.7
redhat
больше 2 лет назад

In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.

CVSS3: 3.7
nvd
больше 2 лет назад

In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.

CVSS3: 3.7
msrc
6 месяцев назад

Описание отсутствует

suse-cvrf
больше 2 лет назад

Security update for postgresql14

EPSS

Процентиль: 40%
0.00181
Низкий