Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-41862


In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.


Published

2023-03-03T16:15:09.497

Last Modified

2025-03-07T16:15:36.247

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.7 (LOW)

Weaknesses
  • Type: Secondary
    CWE-200
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application postgresql postgresql < 12.14 Yes
Application postgresql postgresql < 13.10 Yes
Application postgresql postgresql < 14.7 Yes
Application postgresql postgresql < 15.2 Yes
Operating System fedoraproject fedora 8 Yes
Application redhat integration_camel_k - Yes
Application redhat integration_camel_quarkus - Yes
Application redhat integration_service_registry - Yes
Operating System redhat enterprise_linux 8.0 Yes

References