In PostgreSQL, a modified, unauthenticated server can...
Low severity
Unreviewed
Published
Mar 3, 2023
to the GitHub Advisory Database
•
Updated Apr 27, 2023
Description
Published by the National Vulnerability Database
Mar 3, 2023
Published to the GitHub Advisory Database
Mar 3, 2023
Last updated
Apr 27, 2023
In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.
References