CVE-2022-41862Sensitive Information Exposure in Postgresql

Severity
3.7LOWNVD
EPSS
0.3%
top 44.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 3
Latest updateFeb 15

Description

In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 2.2 | Impact: 1.4

Affected Packages2 packages

NVDpostgresql/postgresql12.012.14+3
CVEListV5postgresql/postgresqlpostgresql 5.2, postgresql 14.7, postgresql 13.10, postgresql 12.14, postgresql 11.19

Also affects: Fedora 8, Enterprise Linux 8.0

🔴Vulnerability Details

3
GHSA
GHSA-fr68-cm8v-7vv6: In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption2023-03-03
OSV
CVE-2022-41862: In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption2023-03-03
CVEList
CVE-2022-41862: In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption2023-03-03

📋Vendor Advisories

5
CISA ICS
Siemens SCALANCE XCM-/XRM-3002024-02-15
Microsoft
In PostgreSQL a modified unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to ov2023-03-14
Ubuntu
PostgreSQL vulnerability2023-03-02
Red Hat
postgresql: Client memory disclosure when connecting with Kerberos to modified server2023-02-09
Debian
CVE-2022-41862: postgresql-13 - In PostgreSQL, a modified, unauthenticated server can send an unterminated strin...2022
CVE-2022-41862 — Sensitive Information Exposure | cvebase