postgresql-server -- Buffer overrun from integer overflow in array modification

Affected packages
postgresql-server < 16.1
postgresql-server < 15.5
postgresql-server < 14.10
postgresql-server < 13.13
postgresql-server < 12.17
postgresql-server < 11.22


VuXML ID 0f445859-7f0e-11ee-94b4-6cc21735f730
Discovery 2023-11-09
Entry 2023-11-09

PostgreSQL Project reports:

While modifying certain SQL array values, missing overflow checks let authenticated database users write arbitrary bytes to a memory area that facilitates arbitrary code execution. Missing overflow checks also let authenticated database users read a wide area of server memory. The CVE-2021-32027 fix covered some attacks of this description, but it missed others.


CVE Name CVE-2023-5869