MEDIUM · 4.3

CVE-2023-5868

A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handlin...

Vulnerability Description

A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.

CVSS Score

4.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
PostgresqlPostgresql>= 11.0, < 11.22
RedhatCodeready Linux Builder Eus9.2
RedhatCodeready Linux Builder Eus For Power Little Endian Eus9.0_ppc64le
RedhatCodeready Linux Builder For Arm64 Eus8.6_aarch64
RedhatCodeready Linux Builder For Ibm Z Systems Eus9.0_s390x
RedhatCodeready Linux Builder For Power Little Endian Eus9.0_ppc64le
RedhatSoftware Collections1.0
RedhatEnterprise Linux8.0
RedhatEnterprise Linux Eus8.6
RedhatEnterprise Linux For Arm 648.0
RedhatEnterprise Linux For Ibm Z Systems8.0_s390x
RedhatEnterprise Linux For Ibm Z Systems Eus8.6_s390x
RedhatEnterprise Linux For Power Little Endian8.0_ppc64le
RedhatEnterprise Linux For Power Little Endian Eus8.6_ppc64le
RedhatEnterprise Linux Server Aus8.2
RedhatEnterprise Linux Server Tus8.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-5868?

CVE-2023-5868 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handlin...

How severe is CVE-2023-5868?

CVE-2023-5868 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-5868?

Check the references section above for vendor advisories and patch information. Affected products include: Postgresql Postgresql, Redhat Codeready Linux Builder Eus, Redhat Codeready Linux Builder Eus For Power Little Endian Eus, Redhat Codeready Linux Builder For Arm64 Eus, Redhat Codeready Linux Builder For Ibm Z Systems Eus.