V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2023-5868
AST
Medium

A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain ag…

CVSS
4.3
Medium
EPSS
0.03
p84
Published
2023-01-01
Updated
2023-01-01
Description

A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.

Tags · CWE
CWE-686
Affected products
PostgresqlPostgresqlPostgresqlPostgresqlPostgresqlPostgresqlPostgresqlPostgresqlPostgresqlPostgresqlPostgresqlPostgresqlPostgresqlPostgresqlPostgresqlPostgresqlPostgresqlPostgresqlPostgresqlPostgresql
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.028 · p84
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
Showing first 20 of 58
Source databases
AST
DEB
CVE
RED
UBU
Related vulnerabilities