• CVE-2023-5868

发布时间: 2024年11月22日

修改时间: 2024年11月22日

概要

A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.

CVSS v3 指标

NVD openEuler
CVSS评分 4.3 4.3
Attack Vector Network Network
Attack Complexity Low Low
Privileges Required Low Low
User Interaction None None
Scope Unchanged Unchanged
Confidentiality Low Low
Integrity None None
Availability None None

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-4218 libpq security update 2024年11月22日

影响产品

产品 状态
KY3.5.2 libpq Fixed