CVE-2022-41862
Published: 10 February 2023
In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.
Notes
Author | Note |
---|---|
leosilva | PostgreSQL 9.3 is end of life upstream, and no updates are are available. Marking as deferred in -esm-main releases. |
mdeslaur | postgresql-10 does not contain GSSAPI encryption support |
Priority
Status
Package | Release | Status |
---|---|---|
postgresql-12 Launchpad, Ubuntu, Debian |
focal |
Released
(12.14-0ubuntu0.20.04.1)
|
trusty |
Ignored
(end of standard support)
|
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
upstream |
Released
(12.14)
|
|
postgresql-14 Launchpad, Ubuntu, Debian |
jammy |
Released
(14.7-0ubuntu0.22.04.1)
|
kinetic |
Released
(14.7-0ubuntu0.22.10.1)
|
|
xenial |
Does not exist
|
|
trusty |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
upstream |
Released
(14.7)
|
|
postgresql-9.1 Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
trusty |
Ignored
(end of standard support)
|
|
upstream |
Not vulnerable
(code not present)
|
|
xenial |
Does not exist
|
|
postgresql-9.3 Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
trusty |
Not vulnerable
(code not present)
|
|
upstream |
Not vulnerable
(code not present)
|
|
xenial |
Does not exist
|
|
postgresql-9.5 Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
(code not present)
|
|
xenial |
Not vulnerable
(code not present)
|
|
postgresql-10 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Not vulnerable
(code not present)
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
upstream |
Not vulnerable
(code not present)
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 3.7 |
Attack vector | Network |
Attack complexity | High |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | Low |
Integrity impact | None |
Availability impact | None |
Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |