Куда я попал?
CVE-2023-5869
PUBLISHED
15.11.2024
CNA: redhat
Postgresql: buffer overrun from integer overflow in array modification
Обновлено:
15.11.2024
A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data. This enables the execution of arbitrary code on the target system, allowing users to write arbitrary bytes to memory and extensively read the server's memory.
CWE
Идентификатор | Описание |
---|---|
CWE-190 | Целочисленное переполнение или циклический возврат |
БДУ ФСТЭК
Идентификатор | Описание |
---|---|
BDU:2023-07840 | Уязвимость функций array_append, array_prepend, array_subscript_handler системы управления базами данных PostgreSQL, связанная с целочисленным переполнением при модификации массивов, позволяющая нарушителю выполнить произвольный код |
НКЦКИ уязвимости
Бюллетени НКЦКИ - уязвимости ПО
Идентификатор | Дата бюллетеня | Описание |
---|---|---|
VULN:20231110-11 | 10.11.2023 | Выполнение произвольного кода в PostgreSQL |
CVSS
Оценка | Severity | Версия | Базовый вектор |
---|---|---|---|
8.8 | HIGH | 3.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Доп. Информация
Product Status
Red Hat Advanced Cluster Security 4.2 | |||||
---|---|---|---|---|---|
Product: | Red Hat Advanced Cluster Security 4.2 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Advanced Cluster Security 4.2 | |||||
---|---|---|---|---|---|
Product: | Red Hat Advanced Cluster Security 4.2 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Advanced Cluster Security 4.2 | |||||
---|---|---|---|---|---|
Product: | Red Hat Advanced Cluster Security 4.2 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Advanced Cluster Security 4.2 | |||||
---|---|---|---|---|---|
Product: | Red Hat Advanced Cluster Security 4.2 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Advanced Cluster Security 4.2 | |||||
---|---|---|---|---|---|
Product: | Red Hat Advanced Cluster Security 4.2 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 7 | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 7 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8 | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8 | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8 | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8 | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.2 Advanced Update Support | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.2 Advanced Update Support | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.2 Advanced Update Support | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.2 Advanced Update Support | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.2 Telecommunications Update Service | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.2 Telecommunications Update Service | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.2 Telecommunications Update Service | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.2 Telecommunications Update Service | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.4 Telecommunications Update Service | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.4 Telecommunications Update Service | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.4 Telecommunications Update Service | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.4 Telecommunications Update Service | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.4 Telecommunications Update Service | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.4 Telecommunications Update Service | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.6 Extended Update Support | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.6 Extended Update Support | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.6 Extended Update Support | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.6 Extended Update Support | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.6 Extended Update Support | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.6 Extended Update Support | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.8 Extended Update Support | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.8 Extended Update Support | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.8 Extended Update Support | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.8 Extended Update Support | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.8 Extended Update Support | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.8 Extended Update Support | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 8.8 Extended Update Support | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8.8 Extended Update Support | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 9 | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 9 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 9 | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 9 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 9.0 Extended Update Support | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 9.0 Extended Update Support | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 9.2 Extended Update Support | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 9.2 Extended Update Support | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 9.2 Extended Update Support | |||||
---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 9.2 Extended Update Support | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Software Collections for Red Hat Enterprise Linux 7 | |||||
---|---|---|---|---|---|
Product: | Red Hat Software Collections for Red Hat Enterprise Linux 7 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Software Collections for Red Hat Enterprise Linux 7 | |||||
---|---|---|---|---|---|
Product: | Red Hat Software Collections for Red Hat Enterprise Linux 7 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Software Collections for Red Hat Enterprise Linux 7 | |||||
---|---|---|---|---|---|
Product: | Red Hat Software Collections for Red Hat Enterprise Linux 7 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
RHACS-3.74-RHEL-8 | |||||
---|---|---|---|---|---|
Product: | RHACS-3.74-RHEL-8 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
RHACS-3.74-RHEL-8 | |||||
---|---|---|---|---|---|
Product: | RHACS-3.74-RHEL-8 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
RHACS-3.74-RHEL-8 | |||||
---|---|---|---|---|---|
Product: | RHACS-3.74-RHEL-8 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
RHACS-3.74-RHEL-8 | |||||
---|---|---|---|---|---|
Product: | RHACS-3.74-RHEL-8 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
RHACS-3.74-RHEL-8 | |||||
---|---|---|---|---|---|
Product: | RHACS-3.74-RHEL-8 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
RHACS-4.1-RHEL-8 | |||||
---|---|---|---|---|---|
Product: | RHACS-4.1-RHEL-8 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
RHACS-4.1-RHEL-8 | |||||
---|---|---|---|---|---|
Product: | RHACS-4.1-RHEL-8 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
RHACS-4.1-RHEL-8 | |||||
---|---|---|---|---|---|
Product: | RHACS-4.1-RHEL-8 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
RHACS-4.1-RHEL-8 | |||||
---|---|---|---|---|---|
Product: | RHACS-4.1-RHEL-8 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
RHACS-4.1-RHEL-8 | |||||
---|---|---|---|---|---|
Product: | RHACS-4.1-RHEL-8 | ||||
Vendor: | Red Hat | ||||
Default status: | affected | ||||
Версии: |
|
||||
СPE: |
|
Red Hat Enterprise Linux 6 | |
---|---|
Product: | Red Hat Enterprise Linux 6 |
Vendor: | Red Hat |
Default status: | unknown |
СPE: |
|
Red Hat Enterprise Linux 8 | |
---|---|
Product: | Red Hat Enterprise Linux 8 |
Vendor: | Red Hat |
Default status: | unaffected |
СPE: |
|
Red Hat Enterprise Linux 9 | |
---|---|
Product: | Red Hat Enterprise Linux 9 |
Vendor: | Red Hat |
Default status: | unaffected |
СPE: |
|
Ссылки
CVE Program Container
Обновлено:
02.08.2024
SSVC and KEV, plus CVSS and CWE if not provided by the CNA.
Ссылки
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.