CVE-2022-41862

CVSS V2 None CVSS V3 None
Description
In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.
Overview
  • CVE ID
  • CVE-2022-41862
  • Assigner
  • secalert@redhat.com
  • Vulnerability Status
  • Modified
  • Published Version
  • 2023-03-03T16:15:09
  • Last Modified Date
  • 2023-04-27T15:15:09
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 1 OR 12.0 12.14
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 1 OR 13.0 13.10
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 1 OR 14.0 14.7
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 1 OR 15.0 15.2
cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:integration_camel_k:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:integration_camel_quarkus:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:integration_service_registry:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* 1 OR
History
Created Old Value New Value Data Type Notes
2023-04-17 05:53:47 Added to TrackCVE
2023-04-17 05:53:49 Weakness Enumeration new
2023-04-27 16:02:53 2023-04-27T15:15:09 CVE Modified Date updated
2023-04-27 16:02:53 Analyzed Modified Vulnerability Status updated
2023-04-27 16:02:55 References updated