4.3
CVE-2023-5868
- EPSS 2.78%
- Veröffentlicht 10.12.2023 18:15:07
- Zuletzt bearbeitet 23.06.2026 18:17:37
- Erkennungen
Postgresql: memory disclosure in aggregate function calls
A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Postgresql ≫ Postgresql Version >= 11.0 < 11.22
Postgresql ≫ Postgresql Version >= 12.0 < 12.17
Postgresql ≫ Postgresql Version >= 13.0 < 13.13
Postgresql ≫ Postgresql Version >= 14.0 < 14.10
Postgresql ≫ Postgresql Version >= 15.0 < 15.5
Postgresql ≫ Postgresql Version 16.0
Redhat ≫ Codeready Linux Builder Eus Version 9.2
Redhat ≫ Codeready Linux Builder Eus For Power Little Endian Eus Version 9.0_ppc64le
Redhat ≫ Codeready Linux Builder Eus For Power Little Endian Eus Version 9.2_ppc64le
Redhat ≫ Codeready Linux Builder For Arm64 Eus Version 8.6_aarch64
Redhat ≫ Codeready Linux Builder For Arm64 Eus Version 9.0_aarch64
Redhat ≫ Codeready Linux Builder For Arm64 Eus Version 9.2_aarch64
Redhat ≫ Codeready Linux Builder For Ibm Z Systems Eus Version 9.0_s390x
Redhat ≫ Codeready Linux Builder For Ibm Z Systems Eus Version 9.2_s390x
Redhat ≫ Codeready Linux Builder For Power Little Endian Eus Version 9.0_ppc64le
Redhat ≫ Codeready Linux Builder For Power Little Endian Eus Version 9.2_ppc64le
Redhat ≫ Software Collections Version 1.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Enterprise Linux Eus Version 8.6
Redhat ≫ Enterprise Linux Eus Version 8.8
Redhat ≫ Enterprise Linux Eus Version 9.0
Redhat ≫ Enterprise Linux Eus Version 9.2
Redhat ≫ Enterprise Linux For Arm 64 Version 8.0
Redhat ≫ Enterprise Linux For Arm 64 Version 8.8_aarch64
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 8.0_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 8.6_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 8.8_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 9.0_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 9.2_s390x
Redhat ≫ Enterprise Linux For Power Little Endian Version 8.0_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.6_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.8_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 9.0_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 9.2_ppc64le
Redhat ≫ Enterprise Linux Server Aus Version 8.2
Redhat ≫ Enterprise Linux Server Aus Version 8.4
Redhat ≫ Enterprise Linux Server Aus Version 8.6
Redhat ≫ Enterprise Linux Server Aus Version 9.2
Redhat ≫ Enterprise Linux Server Tus Version 8.2
Redhat ≫ Enterprise Linux Server Tus Version 8.4
Redhat ≫ Enterprise Linux Server Tus Version 8.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.78% | 0.852 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| RedHat | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-686 Function Call With Incorrect Argument Type
The product calls a function, procedure, or routine, but the caller specifies an argument that is the wrong data type, which may lead to resultant weaknesses.
https://access.redhat.com/errata/RHSA-2023:7545
https://access.redhat.com/errata/RHSA-2023:7579
https://access.redhat.com/errata/RHSA-2023:7580
https://access.redhat.com/errata/RHSA-2023:7581
https://access.redhat.com/errata/RHSA-2023:7616
https://access.redhat.com/errata/RHSA-2023:7656
https://access.redhat.com/errata/RHSA-2023:7666
https://access.redhat.com/errata/RHSA-2023:7667
https://access.redhat.com/errata/RHSA-2023:7694
https://access.redhat.com/errata/RHSA-2023:7695
https://access.redhat.com/errata/RHSA-2023:7714
https://access.redhat.com/errata/RHSA-2023:7770
https://access.redhat.com/errata/RHSA-2023:7772
https://access.redhat.com/errata/RHSA-2023:7784
https://access.redhat.com/errata/RHSA-2023:7785
https://access.redhat.com/errata/RHSA-2023:7883
https://access.redhat.com/errata/RHSA-2023:7884
https://access.redhat.com/errata/RHSA-2023:7885
https://access.redhat.com/errata/RHSA-2024:0304
https://access.redhat.com/errata/RHSA-2024:0332
https://access.redhat.com/errata/RHSA-2024:0337
https://access.redhat.com/security/cve/CVE-2023-5868
https://bugzilla.redhat.com/show_bug.cgi?id=2247168
https://www.postgresql.org/about/news/postgresql-161-155-1410-1313-1217-and-1122-released-2749/
https://www.postgresql.org/support/security/CVE-2023-5868/
https://security.netapp.com/advisory/ntap-20240119-0003/
https://lists.debian.org/debian-lts-announce/2023/11/msg00007.html