In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.
2023-03-03T16:15:09.497
2025-03-07T16:15:36.247
Modified
CVSSv3.1: 3.7 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | postgresql | postgresql | < 12.14 | Yes |
Application | postgresql | postgresql | < 13.10 | Yes |
Application | postgresql | postgresql | < 14.7 | Yes |
Application | postgresql | postgresql | < 15.2 | Yes |
Operating System | fedoraproject | fedora | 8 | Yes |
Application | redhat | integration_camel_k | - | Yes |
Application | redhat | integration_camel_quarkus | - | Yes |
Application | redhat | integration_service_registry | - | Yes |
Operating System | redhat | enterprise_linux | 8.0 | Yes |