CVE Vulnerabilities

CVE-2022-41862

Published: Mar 03, 2023 | Modified: Apr 27, 2023
CVSS 3.x
3.7
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
3.7 LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu
MEDIUM

In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.

Affected Software

Name Vendor Start Version End Version
Postgresql Postgresql 12.0 (including) 12.14 (excluding)
Postgresql Postgresql 13.0 (including) 13.10 (excluding)
Postgresql Postgresql 14.0 (including) 14.7 (excluding)
Postgresql Postgresql 15.0 (including) 15.2 (excluding)
Red Hat Enterprise Linux 8 RedHat postgresql:13-8070020230227142544.bd1311ed *
Red Hat Enterprise Linux 8 RedHat postgresql:12-8080020230717103820.63b34585 *
Red Hat Enterprise Linux 8 RedHat libpq-0:13.11-1.el8 *
Red Hat Enterprise Linux 8.2 Advanced Update Support RedHat postgresql:12-8020020231128165246.4cda2c84 *
Red Hat Enterprise Linux 8.2 Telecommunications Update Service RedHat postgresql:12-8020020231128165246.4cda2c84 *
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions RedHat postgresql:12-8020020231128165246.4cda2c84 *
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support RedHat postgresql:12-8040020231127153301.522a0ee4 *
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support RedHat postgresql:13-8040020231127154806.522a0ee4 *
Red Hat Enterprise Linux 8.4 Telecommunications Update Service RedHat postgresql:12-8040020231127153301.522a0ee4 *
Red Hat Enterprise Linux 8.4 Telecommunications Update Service RedHat postgresql:13-8040020231127154806.522a0ee4 *
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions RedHat postgresql:12-8040020231127153301.522a0ee4 *
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions RedHat postgresql:13-8040020231127154806.522a0ee4 *
Red Hat Enterprise Linux 8.6 Extended Update Support RedHat postgresql:13-8060020231114115246.ad008a3a *
Red Hat Enterprise Linux 8.6 Extended Update Support RedHat postgresql:12-8060020231128165328.ad008a3a *
Red Hat Enterprise Linux 9 RedHat postgresql-0:13.10-1.el9_1 *
Red Hat Enterprise Linux 9 RedHat libpq-0:13.11-1.el9 *
Red Hat Enterprise Linux 9.0 Extended Update Support RedHat postgresql-0:13.13-1.el9_0 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-postgresql13-postgresql-0:13.13-1.el7 *
Postgresql-12 Ubuntu focal *
Postgresql-12 Ubuntu trusty *
Postgresql-12 Ubuntu upstream *
Postgresql-14 Ubuntu jammy *
Postgresql-14 Ubuntu kinetic *
Postgresql-14 Ubuntu upstream *
Postgresql-9.1 Ubuntu trusty *
Postgresql-9.3 Ubuntu trusty *
Postgresql-9.5 Ubuntu xenial *

References