cbcvebase.
CVE-2022-41862
published 2023-03-03

CVE-2022-41862: In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain…

low3.7CVSS 3.1
AVNACHPRNUINSUCLINAN
In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianpostgresql-13< postgresql-13 13.10-0+deb11u1 (bullseye)postgresql-13 13.10-0+deb11u1 (bullseye)
debianpostgresql-15< postgresql-13 13.10-0+deb11u1 (bullseye)postgresql-13 13.10-0+deb11u1 (bullseye)
fedoraprojectfedora
msrccbl2_postgresql_14.10-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_postgresql_12.15-1_on_cbl_mariner_1.0
postgresqlpostgresql
postgresqlpostgresql>= 12.0 < 12.1412.14
postgresqlpostgresql>= 13.0 < 13.1013.10
postgresqlpostgresql>= 14.0 < 14.714.7
postgresqlpostgresql>= 15.0 < 15.215.2
redhatenterprise_linux

CVSS provenance

nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
osv3.7LOW