CVE-2023-5868
published 2023-12-10CVE-2023-5868: A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function…
PriorityP424medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
2.77%
84.7th percentile
A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | postgresql-13 | < postgresql-13 13.13-0+deb11u1 (bullseye) | postgresql-13 13.13-0+deb11u1 (bullseye) |
| debian | postgresql-15 | < postgresql-13 13.13-0+deb11u1 (bullseye) | postgresql-13 13.13-0+deb11u1 (bullseye) |
| msrc | cbl2_postgresql_14.10-1_on_cbl_mariner_2.0 | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | >= 11.0 < 11.22 | 11.22 |
| postgresql | postgresql | >= 12.0 < 12.17 | 12.17 |
| postgresql | postgresql | >= 13.0 < 13.13 | 13.13 |
| postgresql | postgresql | >= 14.0 < 14.10 | 14.10 |
| postgresql | postgresql | >= 15.0 < 15.5 | 15.5 |
| redhat | codeready_linux_builder_eus | — | — |
| redhat | codeready_linux_builder_eus_for_power_little_endian_eus | — | — |
| redhat | codeready_linux_builder_eus_for_power_little_endian_eus | — | — |
| redhat | codeready_linux_builder_for_arm64_eus | — | — |
| redhat | codeready_linux_builder_for_arm64_eus | — | — |
| redhat | codeready_linux_builder_for_arm64_eus | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems_eus | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems_eus | — | — |
| redhat | codeready_linux_builder_for_power_little_endian_eus | — | — |
| redhat | codeready_linux_builder_for_power_little_endian_eus | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_msrc4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-08-15·CVSS 7.0
[HIGH] Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateAugust 15, 2024
Alert CodeICSA-24-228-06
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.4
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Use After Free, Improper Input Validation, Deserialization of Untrusted Data, Improper Restriction of Operations
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2024-01-17·CVSS 4.3
CVE-2023-5868 [MEDIUM] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: Several security issues were fixed in PostgreSQL.
USN-6538-1 fixed several vulnerabilities in PostgreSQL. This update provides
the corresponding updates for Ubuntu 18.04 LTS.
Original advisory details:
Jingzhou Fu discovered that PostgreSQL incorrectly handled certain unknown
arguments in aggregate function calls. A remote attacker could possibly use
this issue to obtain sensitive information. (CVE-2023-5868)
Pedro Gallegos discovered that PostgreSQL incorrectly handled modifying
certain SQL array values. A remote attacker could use this issue to obtain
sensitive information, or possibly execute arbitrary code. (CVE-2023-5869)
Hemanth Sandrana and Mahendrakar Srinivasarao discovered that PostgreSQL
allowed the pg_signal_backend role to signa
Microsoft
Postgresql: memory disclosure in aggregate function calls
vendor_msrc·2023-12-12·CVSS 4.3
CVE-2023-5868 [MEDIUM] CWE-686 Postgresql: memory disclosure in aggregate function calls
Postgresql: memory disclosure in aggregate function calls
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://l
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2023-12-06·CVSS 4.3
CVE-2023-5869 [MEDIUM] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: Several security issues were fixed in PostgreSQL.
Jingzhou Fu discovered that PostgreSQL incorrectly handled certain unknown
arguments in aggregate function calls. A remote attacker could possibly use
this issue to obtain sensitive information. (CVE-2023-5868)
Pedro Gallegos discovered that PostgreSQL incorrectly handled modifying
certain SQL array values. A remote attacker could use this issue to obtain
sensitive information, or possibly execute arbitrary code. (CVE-2023-5869)
Hemanth Sandrana and Mahendrakar Srinivasarao discovered that PostgreSQL
allowed the pg_signal_backend role to signal certain superuser processes,
contrary to expectations. (CVE-2023-5870)
Instructions: This update uses a new upstream release, which includes additional
Red Hat
postgresql: Memory disclosure in aggregate function calls
vendor_redhat·2023-11-09·CVSS 4.3
CVE-2023-5868 [MEDIUM] CWE-686 postgresql: Memory disclosure in aggregate function calls
postgresql: Memory disclosure in aggregate function calls
A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.
A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without
Debian
CVE-2023-5868: postgresql-13 - A memory disclosure vulnerability was found in PostgreSQL that allows remote use...
vendor_debian·2023·CVSS 4.3
CVE-2023-5868 [MEDIUM] CVE-2023-5868: postgresql-13 - A memory disclosure vulnerability was found in PostgreSQL that allows remote use...
A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.
Scope: local
bullseye: resolved (fixed in 13.13-0+deb11u1)
OSV
postgresql-10 vulnerabilities
osv·2024-01-17·CVSS 4.3
CVE-2023-5868 [MEDIUM] postgresql-10 vulnerabilities
postgresql-10 vulnerabilities
USN-6538-1 fixed several vulnerabilities in PostgreSQL. This update provides
the corresponding updates for Ubuntu 18.04 LTS.
Original advisory details:
Jingzhou Fu discovered that PostgreSQL incorrectly handled certain unknown
arguments in aggregate function calls. A remote attacker could possibly use
this issue to obtain sensitive information. (CVE-2023-5868)
Pedro Gallegos discovered that PostgreSQL incorrectly handled modifying
certain SQL array values. A remote attacker could use this issue to obtain
sensitive information, or possibly execute arbitrary code. (CVE-2023-5869)
Hemanth Sandrana and Mahendrakar Srinivasarao discovered that PostgreSQL
allowed the pg_signal_backend role to signal certain superuser processes,
contrary to expectations. (CVE-20
GHSA
GHSA-3f9w-7983-qcmq: A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate fun
ghsa_unreviewed·2023-12-10
CVE-2023-5868 [MEDIUM] CWE-686 GHSA-3f9w-7983-qcmq: A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate fun
A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.
OSV
CVE-2023-5868: A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate fun
osv·2023-12-10·CVSS 4.3
CVE-2023-5868 [MEDIUM] CVE-2023-5868: A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate fun
A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.
OSV
postgresql-12, postgresql-14, postgresql-15 vulnerabilities
osv·2023-12-06·CVSS 4.3
CVE-2023-5868 [MEDIUM] postgresql-12, postgresql-14, postgresql-15 vulnerabilities
postgresql-12, postgresql-14, postgresql-15 vulnerabilities
Jingzhou Fu discovered that PostgreSQL incorrectly handled certain unknown
arguments in aggregate function calls. A remote attacker could possibly use
this issue to obtain sensitive information. (CVE-2023-5868)
Pedro Gallegos discovered that PostgreSQL incorrectly handled modifying
certain SQL array values. A remote attacker could use this issue to obtain
sensitive information, or possibly execute arbitrary code. (CVE-2023-5869)
Hemanth Sandrana and Mahendrakar Srinivasarao discovered that PostgreSQL
allowed the pg_signal_backend role to signal certain superuser processes,
contrary to expectations. (CVE-2023-5870)
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2023:7545https://access.redhat.com/errata/RHSA-2023:7579https://access.redhat.com/errata/RHSA-2023:7580https://access.redhat.com/errata/RHSA-2023:7581https://access.redhat.com/errata/RHSA-2023:7616https://access.redhat.com/errata/RHSA-2023:7656https://access.redhat.com/errata/RHSA-2023:7666https://access.redhat.com/errata/RHSA-2023:7667https://access.redhat.com/errata/RHSA-2023:7694https://access.redhat.com/errata/RHSA-2023:7695https://access.redhat.com/errata/RHSA-2023:7714https://access.redhat.com/errata/RHSA-2023:7770https://access.redhat.com/errata/RHSA-2023:7772https://access.redhat.com/errata/RHSA-2023:7784https://access.redhat.com/errata/RHSA-2023:7785https://access.redhat.com/errata/RHSA-2023:7883https://access.redhat.com/errata/RHSA-2023:7884https://access.redhat.com/errata/RHSA-2023:7885https://access.redhat.com/errata/RHSA-2024:0304https://access.redhat.com/errata/RHSA-2024:0332https://access.redhat.com/errata/RHSA-2024:0337https://access.redhat.com/security/cve/CVE-2023-5868https://bugzilla.redhat.com/show_bug.cgi?id=2247168https://www.postgresql.org/about/news/postgresql-161-155-1410-1313-1217-and-1122-released-2749/https://www.postgresql.org/support/security/CVE-2023-5868/https://access.redhat.com/errata/RHSA-2023:7545https://access.redhat.com/errata/RHSA-2023:7579https://access.redhat.com/errata/RHSA-2023:7580https://access.redhat.com/errata/RHSA-2023:7581https://access.redhat.com/errata/RHSA-2023:7616https://access.redhat.com/errata/RHSA-2023:7656https://access.redhat.com/errata/RHSA-2023:7666https://access.redhat.com/errata/RHSA-2023:7667https://access.redhat.com/errata/RHSA-2023:7694https://access.redhat.com/errata/RHSA-2023:7695https://access.redhat.com/errata/RHSA-2023:7714https://access.redhat.com/errata/RHSA-2023:7770https://access.redhat.com/errata/RHSA-2023:7772https://access.redhat.com/errata/RHSA-2023:7784https://access.redhat.com/errata/RHSA-2023:7785https://access.redhat.com/errata/RHSA-2023:7883https://access.redhat.com/errata/RHSA-2023:7884https://access.redhat.com/errata/RHSA-2023:7885https://access.redhat.com/errata/RHSA-2024:0304https://access.redhat.com/errata/RHSA-2024:0332https://access.redhat.com/errata/RHSA-2024:0337https://access.redhat.com/security/cve/CVE-2023-5868https://bugzilla.redhat.com/show_bug.cgi?id=2247168https://lists.debian.org/debian-lts-announce/2023/11/msg00007.htmlhttps://security.netapp.com/advisory/ntap-20240119-0003/https://www.postgresql.org/about/news/postgresql-161-155-1410-1313-1217-and-1122-released-2749/https://www.postgresql.org/support/security/CVE-2023-5868/
2023-12-10
Published