Описание
A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat build of Quarkus | postgresql | Not affected | ||
Red Hat Decision Manager 7 | postgresql | Not affected | ||
Red Hat Enterprise Linux 6 | postgresql | Out of support scope | ||
Red Hat Enterprise Linux 7 | postgresql | Out of support scope | ||
Red Hat Enterprise Linux 8 | libpq | Not affected | ||
Red Hat Enterprise Linux 8 | postgresql:10/postgresql | Not affected | ||
Red Hat Enterprise Linux 8 | postgresql:9.6/postgresql | Not affected | ||
Red Hat Enterprise Linux 9 | postgresql | Not affected | ||
Red Hat Fuse 7 | postgresql | Not affected | ||
Red Hat JBoss Enterprise Application Platform 6 | postgresql | Out of support scope |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.
A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.
A flaw was found in postgresql. Using an UPDATE ... RETURNING command ...
A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.
Уязвимость реализации команды UPDATE ... RETURNING системы управления базами данных PostgreSQL, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
6.5 Medium
CVSS3