Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-5869

Опубликовано: 09 нояб. 2023
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data. This enables the execution of arbitrary code on the target system, allowing users to write arbitrary bytes to memory and extensively read the server's memory.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6postgresqlOut of support scope
Red Hat Enterprise Linux 8postgresql:16/postgresqlNot affected
Red Hat Enterprise Linux 9postgresql:16/postgresqlNot affected
Red Hat Advanced Cluster Security 4.2advanced-cluster-security/rhacs-central-db-rhel8FixedRHSA-2024:033722.01.2024
Red Hat Advanced Cluster Security 4.2advanced-cluster-security/rhacs-main-rhel8FixedRHSA-2024:033722.01.2024
Red Hat Advanced Cluster Security 4.2advanced-cluster-security/rhacs-operator-bundleFixedRHSA-2024:033722.01.2024
Red Hat Advanced Cluster Security 4.2advanced-cluster-security/rhacs-scanner-db-rhel8FixedRHSA-2024:033722.01.2024
Red Hat Advanced Cluster Security 4.2advanced-cluster-security/rhacs-scanner-db-slim-rhel8FixedRHSA-2024:033722.01.2024
Red Hat Enterprise Linux 7postgresqlFixedRHSA-2023:778313.12.2023
Red Hat Enterprise Linux 8postgresqlFixedRHSA-2023:758129.11.2023

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2247169postgresql: Buffer overrun from integer overflow in array modification

EPSS

Процентиль: 81%
0.01608
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 1 года назад

A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data. This enables the execution of arbitrary code on the target system, allowing users to write arbitrary bytes to memory and extensively read the server's memory.

CVSS3: 8.8
nvd
больше 1 года назад

A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data. This enables the execution of arbitrary code on the target system, allowing users to write arbitrary bytes to memory and extensively read the server's memory.

CVSS3: 8.8
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 8.8
debian
больше 1 года назад

A flaw was found in PostgreSQL that allows authenticated database user ...

CVSS3: 8.8
github
больше 1 года назад

A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data. This enables the execution of arbitrary code on the target system, allowing users to write arbitrary bytes to memory and extensively read the server's memory.

EPSS

Процентиль: 81%
0.01608
Низкий

8.8 High

CVSS3