← Back

CVE-2023-5868

nvd nist
Published: Dec 10, 2023Modified: Jun 23, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.

Affected (42)

1 product
Postgresql
15 products
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Postgresql
From 11.0 to 11.22
From 12.0 to 12.17
From 13.0 to 13.13
From 14.0 to 14.10
From 15.0 to 15.5
Version 16.0
Configuration B
36 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.2
Redhat
Version 9.0_ppc64le
Version 9.2_ppc64le
Redhat
Version 8.6_aarch64
Version 9.0_aarch64
Version 9.2_aarch64
Redhat
Version 9.0_s390x
Version 9.2_s390x
Redhat
Version 9.0_ppc64le
Version 9.2_ppc64le
Redhat
Version 8.0
Version 9.0
Redhat
Version 8.6
Version 8.8
Version 9.0
Version 9.2
Redhat
Version 8.0
Version 8.8_aarch64
Version 8.0_s390x
Redhat
Version 8.6_s390x
Version 8.8_s390x
Version 9.0_s390x
Version 9.2_s390x
Version 8.0_ppc64le
Redhat
Version 8.6_ppc64le
Version 8.8_ppc64le
Version 9.0_ppc64le
Version 9.2_ppc64le
Redhat
Version 8.2
Version 8.4
Version 8.6
Version 9.2
Redhat
Version 8.2
Version 8.4
Version 8.6
Version 1.0

References (52)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue Tracking
Source: secalert@redhat.com
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory

Timeline

No history available yet.