CVE-2022-41862
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
03/03/2023
Last modified:
07/03/2025
Description
In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.
Impact
Base Score 3.x
3.70
Severity 3.x
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | 12.0 (including) | 12.14 (excluding) |
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | 13.0 (including) | 13.10 (excluding) |
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | 14.0 (including) | 14.7 (excluding) |
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | 15.0 (including) | 15.2 (excluding) |
cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:* | ||
cpe:2.3:a:redhat:integration_camel_k:-:*:*:*:*:*:*:* | ||
cpe:2.3:a:redhat:integration_camel_quarkus:-:*:*:*:*:*:*:* | ||
cpe:2.3:a:redhat:integration_service_registry:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://bugzilla.redhat.com/show_bug.cgi?id=2165722
- https://security.netapp.com/advisory/ntap-20230427-0002/
- https://www.postgresql.org/support/security/CVE-2022-41862/
- https://bugzilla.redhat.com/show_bug.cgi?id=2165722
- https://security.netapp.com/advisory/ntap-20230427-0002/
- https://www.postgresql.org/support/security/CVE-2022-41862/