Количество 53
Количество 53
CVE-2026-6477
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6477
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6477
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6477
PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory
CVE-2026-6477
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) i ...
RLSA-2026:44391
Important: libpq security update
RLSA-2026:44308
Important: libpq security update
GHSA-jm5f-gpfq-q9h3
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
ELSA-2026-44391
ELSA-2026-44391: libpq security update (IMPORTANT)
ELSA-2026-44308
ELSA-2026-44308: libpq security update (IMPORTANT)
BDU:2026-07098
Уязвимость функции lo_export(), lo_read(), lo_lseek64() и lo_tell64() клиентской библиотеке libpq системы управления базами данных PostgreSQL, позволяющая нарушителю перезаписать память стека pg_dump или psql
ROS-20260708-73-0081
Уязвимость postgresql16
ROS-20260708-73-0017
Уязвимость postgresql18-1c
ROS-20260708-73-0016
Уязвимость postgresql18
ROS-20260708-73-0015
Уязвимость postgresql17-1c
ROS-20260708-73-0014
Уязвимость postgresql17
ROS-20260708-73-0013
Уязвимость postgresql15-1c
ROS-20260708-73-0012
Уязвимость postgresql15
ROS-20260708-73-0011
Уязвимость postgresql-1c
ROS-20260708-73-0010
Уязвимость postgresql14
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-6477 Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-6477 Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-6477 Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-6477 PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-6477 Use of inherently dangerous function PQfn(..., result_is_int=0, ...) i ... | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
RLSA-2026:44391 Important: libpq security update | 0% Низкий | 4 дня назад | ||
RLSA-2026:44308 Important: libpq security update | 0% Низкий | 4 дня назад | ||
GHSA-jm5f-gpfq-q9h3 Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
ELSA-2026-44391 ELSA-2026-44391: libpq security update (IMPORTANT) | 8 дней назад | |||
ELSA-2026-44308 ELSA-2026-44308: libpq security update (IMPORTANT) | 8 дней назад | |||
BDU:2026-07098 Уязвимость функции lo_export(), lo_read(), lo_lseek64() и lo_tell64() клиентской библиотеке libpq системы управления базами данных PostgreSQL, позволяющая нарушителю перезаписать память стека pg_dump или psql | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
ROS-20260708-73-0081 Уязвимость postgresql16 | CVSS3: 8.8 | 0% Низкий | 23 дня назад | |
ROS-20260708-73-0017 Уязвимость postgresql18-1c | CVSS3: 8.8 | 0% Низкий | 23 дня назад | |
ROS-20260708-73-0016 Уязвимость postgresql18 | CVSS3: 8.8 | 0% Низкий | 23 дня назад | |
ROS-20260708-73-0015 Уязвимость postgresql17-1c | CVSS3: 8.8 | 0% Низкий | 23 дня назад | |
ROS-20260708-73-0014 Уязвимость postgresql17 | CVSS3: 8.8 | 0% Низкий | 23 дня назад | |
ROS-20260708-73-0013 Уязвимость postgresql15-1c | CVSS3: 8.8 | 0% Низкий | 23 дня назад | |
ROS-20260708-73-0012 Уязвимость postgresql15 | CVSS3: 8.8 | 0% Низкий | 23 дня назад | |
ROS-20260708-73-0011 Уязвимость postgresql-1c | CVSS3: 8.8 | 0% Низкий | 23 дня назад | |
ROS-20260708-73-0010 Уязвимость postgresql14 | CVSS3: 8.8 | 0% Низкий | 23 дня назад |
Уязвимостей на страницу