Описание
In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.
A flaw was found In PostgreSQL. A modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions, a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз | 
|---|---|---|---|---|
| Red Hat build of Apicurio Registry 2 | quarkus-jdbc-postgresql-deployment | Not affected | ||
| Red Hat build of Quarkus | org.postgresql/postgresql | Not affected | ||
| Red Hat Decision Manager 7 | jdbc-postgresql | Not affected | ||
| Red Hat Enterprise Linux 6 | postgresql-jdbc | Out of support scope | ||
| Red Hat Enterprise Linux 7 | postgresql-jdbc | Out of support scope | ||
| Red Hat Enterprise Linux 8 | libreoffice:flatpak/libreoffice | Fix deferred | ||
| Red Hat Enterprise Linux 8 | postgresql:10/postgresql | Fix deferred | ||
| Red Hat Enterprise Linux 8 | postgresql-jdbc | Not affected | ||
| Red Hat Enterprise Linux 9 | postgresql-jdbc | Not affected | ||
| Red Hat Fuse 7 | jdbc-postgresql | Not affected | 
Показывать по
Дополнительная информация
Статус:
EPSS
3.7 Low
CVSS3
Связанные уязвимости
In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.
In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.
In PostgreSQL, a modified, unauthenticated server can send an untermin ...
EPSS
3.7 Low
CVSS3