We found results for “”
CVE-2023-5868
Good to know:
Date: December 10, 2023
A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.
Language: C
Severity Score
Related Resources (30)
Severity Score
Weakness Type (CWE)
Insufficient Information
NVD-CWE-noinfoFunction Call With Incorrect Argument Type
CWE-686Top Fix
Upgrade Version
Upgrade to version REL_11_22,REL_12_17,REL_13_13,REL_14_10,REL_15_5,REL_16_1
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | NONE |
Availability (A): | NONE |