Total vulnerabilities in the database
In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.
Software | From | Fixed in |
---|---|---|
postgresql / postgresql | 15.0 | 15.2 |
postgresql / postgresql | 14.0 | 14.7 |
postgresql / postgresql | 13.0 | 13.10 |
postgresql / postgresql | 12.0 | 12.14 |
fedoraproject / fedora | 8 | 8.x |
redhat / enterprise_linux | 8.0 | 8.0.x |