CVE-2018-1052Sensitive Information Exposure in Project Postgresql

Severity
6.5MEDIUMNVD
EPSS
0.5%
top 35.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 9
Latest updateMay 13

Description

Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticated attacker to read arbitrary bytes of server memory via purpose-crafted insert to a partitioned table.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

Alpinepostgresql/postgresql< 10.2-r0+7
NVDpostgresql/postgresql10.0, 10.1+1
CVEListV5postgresql_project/postgresql11.x prior to 11.3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-qwcr-cgjv-9rp7: Memory disclosure vulnerability in table partitioning was found in postgresql 102022-05-13
CVEList
CVE-2018-1052: Memory disclosure vulnerability in table partitioning was found in postgresql 102018-02-09
OSV
CVE-2018-1052: Memory disclosure vulnerability in table partitioning was found in postgresql 102018-02-09

📋Vendor Advisories

2
Red Hat
postgresql: Memory disclosure in partition routing2019-05-09
Red Hat
postgresql: Memory disclosure in table partitioning2018-02-08

💬Community

3
Bugzilla
CVE-2019-10129 postgresql: Memory disclosure in partition routing2019-05-06
Bugzilla
CVE-2018-17965 ImageMagick: memory leak in WriteSGIImage in coders/sgi.c2018-10-05
Bugzilla
CVE-2018-1052 postgresql: Memory disclosure in table partitioning2018-01-29
CVE-2018-1052 — Sensitive Information Exposure | cvebase