CVE-2021-32029
published 2021-10-08CVE-2021-32029: A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of…
PriorityP341medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.40%
69.5th percentile
A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | postgresql-13 | < postgresql-13 13.3-1 (bullseye) | postgresql-13 13.3-1 (bullseye) |
| postgresql | postgresql | — | — |
| postgresql | postgresql | >= 11.0 < 11.12 | 11.12 |
| postgresql | postgresql | >= 12.0 < 12.7 | 12.7 |
| postgresql | postgresql | >= 13.0 < 13.3 | 13.3 |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2021-06-01·CVSS 8.8
CVE-2021-32029 [HIGH] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: Several security issues were fixed in PostgreSQL.
Tom Lane discovered that PostgreSQL incorrect handled certain array
subscripting calculations. An authenticated attacker could possibly use
this issue to overwrite server memory and escalate privileges.
(CVE-2021-32027)
Andres Freund discovered that PostgreSQL incorrect handled certain
INSERT ... ON CONFLICT ... DO UPDATE commands. A remote attacker could
possibly use this issue to read server memory and obtain sensitive
information. (CVE-2021-32028)
Tom Lane discovered that PostgreSQL incorrect handled certain UPDATE ...
RETURNING commands. A remote attacker could possibly use this issue to read
server memory and obtain sensitive information. This issue only affected
Ubuntu 20.04 LTS, Ubuntu 2
Red Hat
postgresql: Memory disclosure in partitioned-table UPDATE ... RETURNING
vendor_redhat·2021-05-13·CVSS 6.5
CVE-2021-32029 [MEDIUM] CWE-125 postgresql: Memory disclosure in partitioned-table UPDATE ... RETURNING
postgresql: Memory disclosure in partitioned-table UPDATE ... RETURNING
A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.
A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.
Package: postgresql (Red Hat build of Quarkus) - Not affected
Package: postgresql (Red Hat Decision Manager 7) - Not affected
Package: postgresql (Red Hat Enterprise Linux 6) - Out of support scope
Package: postgresql (Red Hat Enter
Debian
CVE-2021-32029: postgresql-13 - A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpo...
vendor_debian·2021·CVSS 6.5
CVE-2021-32029 [MEDIUM] CVE-2021-32029: postgresql-13 - A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpo...
A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.
Scope: local
bullseye: resolved (fixed in 13.3-1)
GHSA
GHSA-f47v-jjrp-x56x: A flaw was found in postgresql
ghsa_unreviewed·2022-05-24
CVE-2021-32029 [MEDIUM] CWE-125 GHSA-f47v-jjrp-x56x: A flaw was found in postgresql
A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.
OSV
CVE-2021-32029: A flaw was found in postgresql
osv·2021-10-08·CVSS 6.5
CVE-2021-32029 [MEDIUM] CVE-2021-32029: A flaw was found in postgresql
A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.
OSV
postgresql-10, postgresql-12, postgresql-13 vulnerabilities
osv·2021-06-01·CVSS 8.8
CVE-2021-32027 [HIGH] postgresql-10, postgresql-12, postgresql-13 vulnerabilities
postgresql-10, postgresql-12, postgresql-13 vulnerabilities
Tom Lane discovered that PostgreSQL incorrect handled certain array
subscripting calculations. An authenticated attacker could possibly use
this issue to overwrite server memory and escalate privileges.
(CVE-2021-32027)
Andres Freund discovered that PostgreSQL incorrect handled certain
INSERT ... ON CONFLICT ... DO UPDATE commands. A remote attacker could
possibly use this issue to read server memory and obtain sensitive
information. (CVE-2021-32028)
Tom Lane discovered that PostgreSQL incorrect handled certain UPDATE ...
RETURNING commands. A remote attacker could possibly use this issue to read
server memory and obtain sensitive information. This issue only affected
Ubuntu 20.04 LTS, Ubuntu 20.10, and Ubuntu 21.04. (CVE-2021-
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1956883https://security.netapp.com/advisory/ntap-20211112-0003/https://www.postgresql.org/support/security/CVE-2021-32029/https://bugzilla.redhat.com/show_bug.cgi?id=1956883https://security.netapp.com/advisory/ntap-20211112-0003/https://www.postgresql.org/support/security/CVE-2021-32029/
2021-10-08
Published