Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-21469

Опубликовано: 22 авг. 2023
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

An issue was discovered in PostgreSQL 12.2 allows attackers to cause a denial of service via repeatedly sending SIGHUP signals. NOTE: this is disputed by the vendor because untrusted users cannot send SIGHUP signals; they can only be sent by a PostgreSQL superuser, a user with pg_reload_conf access, or a user with sufficient privileges at the OS level (the postgres account or the root account).

A flaw was found in PostgreSQL 12.2. This issue may allow an attacker to cause a denial of service via repeatedly sending SIGHUP signals.

Отчет

This flaw is not actually considered a security vulnerability by upstream and is being disputed. Please check the external reference links for more info.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6postgresqlOut of support scope
Red Hat Enterprise Linux 7postgresqlOut of support scope
Red Hat Enterprise Linux 8postgresql:10/postgresqlFix deferred
Red Hat Enterprise Linux 8postgresql:12/postgresqlFix deferred
Red Hat Enterprise Linux 8postgresql:13/postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:15/postgresqlNot affected
Red Hat Enterprise Linux 9postgresqlNot affected
Red Hat Enterprise Linux 9postgresql:15/postgresqlNot affected
Red Hat Software Collectionsrh-postgresql10-postgresqlFix deferred
Red Hat Software Collectionsrh-postgresql12-postgresqlFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2235010postgresql: Stack buffer overflow when continuously send SIGHUP

EPSS

Процентиль: 5%
0.00024
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
ubuntu
почти 2 года назад

** DISPUTED ** An issue was discovered in PostgreSQL 12.2 allows attackers to cause a denial of service via repeatedly sending SIGHUP signals. NOTE: this is disputed by the vendor because untrusted users cannot send SIGHUP signals; they can only be sent by a PostgreSQL superuser, a user with pg_reload_conf access, or a user with sufficient privileges at the OS level (the postgres account or the root account).

CVSS3: 4.4
nvd
почти 2 года назад

An issue was discovered in PostgreSQL 12.2 allows attackers to cause a denial of service via repeatedly sending SIGHUP signals. NOTE: this is disputed by the vendor because untrusted users cannot send SIGHUP signals; they can only be sent by a PostgreSQL superuser, a user with pg_reload_conf access, or a user with sufficient privileges at the OS level (the postgres account or the root account).

CVSS3: 4.4
debian
почти 2 года назад

An issue was discovered in PostgreSQL 12.2 allows attackers to cause a ...

CVSS3: 7.5
github
почти 2 года назад

An issue was discovered in PostgreSQL 12.2 allows attackers to cause a denial of service via repeatedly sending SIGHUP signals.

CVSS3: 7.5
fstec
почти 2 года назад

Уязвимость обработчика сигнала HUP (SIGHUP) системы управления базами данных PostgreSQL, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 5%
0.00024
Низкий

4.4 Medium

CVSS3