Lucene search

K
postgresqlPostgreSQL Global Development GroupPOSTGRESQL:CVE-2023-5869
HistoryNov 09, 2023 - 12:00 a.m.

Vulnerability in core server (CVE-2023-5869)

2023-11-0900:00:00
PostgreSQL Global Development Group
www.postgresql.org
1
vulnerability
core server
integer overflow
array modification
sql
authenticated users
arbitrary code execution
memory area
postgresql
cve-2023-5869
cve-2021-32027
security fix
pedro gallegos

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9.1

Confidence

High

Buffer overrun from integer overflow in array modification

While modifying certain SQL array values, missing overflow checks let authenticated database users write arbitrary bytes to a memory area that facilitates arbitrary code execution. Missing overflow checks also let authenticated database users read a wide area of server memory. The CVE-2021-32027 fix covered some attacks of this description, but it missed others.

The PostgreSQL project thanks Pedro Gallegos for reporting this problem.

Affected configurations

Vulners
Node
postgresqlpostgresqlRange<16.1
OR
postgresqlpostgresqlRange<14.10
OR
postgresqlpostgresqlRange<15.5
OR
postgresqlpostgresqlRange<13.13
OR
postgresqlpostgresqlRange<12.17
VendorProductVersionCPE
postgresqlpostgresql*cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9.1

Confidence

High