CVE Vulnerabilities

CVE-2022-41862

Published: Mar 03, 2023 | Modified: Apr 27, 2023
CVSS 3.x
3.7
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.

Affected Software

Name Vendor Start Version End Version
Postgresql Postgresql 12.0 (including) 12.14 (excluding)
Postgresql Postgresql 13.0 (including) 13.10 (excluding)
Postgresql Postgresql 14.0 (including) 14.7 (excluding)
Postgresql Postgresql 15.0 (including) 15.2 (excluding)

References