Description
A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0, the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-26969 | A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0, the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting. |
Ubuntu USN |
USN-5038-1 | PostgreSQL vulnerabilities |
References
History
No history.
Subscriptions
Fedoraproject
Subscribe
Fedora
Subscribe
Postgresql
Subscribe
Postgresql
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux For Ibm Z Systems
Subscribe
Enterprise Linux For Power Little Endian
Subscribe
Rhel Software Collections
Subscribe
Rhev Hypervisor
Subscribe
Software Collections
Subscribe
Virtualization
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:01:08.004Z
Reserved: 2021-08-03T00:00:00.000Z
Link: CVE-2021-3677
No data.
Status : Modified
Published: 2022-03-02T23:15:08.900
Modified: 2024-11-21T06:22:08.337
Link: CVE-2021-3677
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN