Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-5870

Опубликовано: 10 дек. 2023
Источник: debian
EPSS Низкий

Описание

A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
postgresql-16fixed16.1-1package
postgresql-15removedpackage
postgresql-13removedpackage
postgresql-11removedpackage

Примечания

  • https://www.postgresql.org/support/security/CVE-2023-5870/

  • https://www.postgresql.org/about/news/postgresql-161-155-1410-1313-1217-and-1122-released-2749/

EPSS

Процентиль: 70%
0.00645
Низкий

Связанные уязвимости

CVSS3: 2.2
ubuntu
больше 1 года назад

A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

CVSS3: 2.2
redhat
больше 1 года назад

A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

CVSS3: 2.2
nvd
больше 1 года назад

A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

CVSS3: 4.4
msrc
7 месяцев назад

Описание отсутствует

CVSS3: 2.2
github
больше 1 года назад

A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

EPSS

Процентиль: 70%
0.00645
Низкий