Количество 40
Количество 40
BDU:2026-07097
Уязвимость системы управления базами данных PostgreSQL, связанная с раскрытием информации на основании временных расхождений, позволяющая нарушителю раскрыть защищаемую информацию
CVE-2026-6478
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6478
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6478
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6478
PostgreSQL discloses MD5-hashed passwords via covert timing channel
CVE-2026-6478
Covert timing channel in comparison of MD5-hashed password in PostgreS ...
RLSA-2026:28208
Important: postgresql:13 security update
GHSA-r6v6-v5r9-3ggh
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
ELSA-2026-28208
ELSA-2026-28208: postgresql:13 security update (IMPORTANT)
RLSA-2026:28999
Important: postgresql:12 security update
RLSA-2026:28143
Important: postgresql:16 security update
ELSA-2026-28999
ELSA-2026-28999: postgresql:12 security update (IMPORTANT)
ELSA-2026-28143
ELSA-2026-28143: postgresql:16 security update (IMPORTANT)
ELSA-2026-26181
ELSA-2026-26181: postgresql:15 security update (IMPORTANT)
RLSA-2026:28037
Important: postgresql:15 security update
RLSA-2026:27743
Important: postgresql16 security update
RLSA-2026:27742
Important: postgresql18 security update
RLSA-2026:27738
Important: libpq security update
RLSA-2026:26204
Important: postgresql:18 security update
RLSA-2026:26203
Important: postgresql:16 security update
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-07097 Уязвимость системы управления базами данных PostgreSQL, связанная с раскрытием информации на основании временных расхождений, позволяющая нарушителю раскрыть защищаемую информацию | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-6478 Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-6478 Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.2 | 0% Низкий | 3 месяца назад | |
CVE-2026-6478 Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-6478 PostgreSQL discloses MD5-hashed passwords via covert timing channel | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-6478 Covert timing channel in comparison of MD5-hashed password in PostgreS ... | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
RLSA-2026:28208 Important: postgresql:13 security update | 0% Низкий | около 1 месяца назад | ||
GHSA-r6v6-v5r9-3ggh Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
ELSA-2026-28208 ELSA-2026-28208: postgresql:13 security update (IMPORTANT) | около 1 месяца назад | |||
RLSA-2026:28999 Important: postgresql:12 security update | около 1 месяца назад | |||
RLSA-2026:28143 Important: postgresql:16 security update | около 1 месяца назад | |||
ELSA-2026-28999 ELSA-2026-28999: postgresql:12 security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-28143 ELSA-2026-28143: postgresql:16 security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-26181 ELSA-2026-26181: postgresql:15 security update (IMPORTANT) | около 1 месяца назад | |||
RLSA-2026:28037 Important: postgresql:15 security update | около 1 месяца назад | |||
RLSA-2026:27743 Important: postgresql16 security update | около 1 месяца назад | |||
RLSA-2026:27742 Important: postgresql18 security update | около 1 месяца назад | |||
RLSA-2026:27738 Important: libpq security update | около 1 месяца назад | |||
RLSA-2026:26204 Important: postgresql:18 security update | около 1 месяца назад | |||
RLSA-2026:26203 Important: postgresql:16 security update | около 1 месяца назад |
Уязвимостей на страницу