CVE-2023-5868

CWE-68611 documents8 sources
Severity
4.3MEDIUM
EPSS
2.7%
top 14.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 10
Latest updateJan 17

Description

A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages9 packages

NVDpostgresql/postgresql11.011.22+5
Debianpostgresql-13< 13.13-0+deb11u1
Debianpostgresql-15< 15.5-0+deb12u1
Ubuntupostgresql-12< 12.17-0ubuntu0.20.04.1
Ubuntupostgresql-14< 14.10-0ubuntu0.22.04.1

Also affects: Enterprise Linux 8.0, 9.0, 8.6, 8.8, 9.2, 8.2, 8.4

🔴Vulnerability Details

5
OSV
postgresql-10 vulnerabilities2024-01-17
CVEList
Postgresql: memory disclosure in aggregate function calls2023-12-10
GHSA
GHSA-3f9w-7983-qcmq: A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate fun2023-12-10
OSV
CVE-2023-5868: A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate fun2023-12-10
OSV
postgresql-12, postgresql-14, postgresql-15 vulnerabilities2023-12-06

📋Vendor Advisories

5
Ubuntu
PostgreSQL vulnerabilities2024-01-17
Microsoft
Postgresql: memory disclosure in aggregate function calls2023-12-12
Ubuntu
PostgreSQL vulnerabilities2023-12-06
Red Hat
postgresql: Memory disclosure in aggregate function calls2023-11-09
Debian
CVE-2023-5868: postgresql-13 - A memory disclosure vulnerability was found in PostgreSQL that allows remote use...2023