CVE-2021-32027
While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory.
The PostgreSQL project thanks Tom Lane for reporting this problem.
Version Information
| Affected branch | Introduced | Fixed In | Fix Published |
|---|
| 10 | — | 10.17 | 2021-05-13 |
| 11 | — | 11.12 | 2021-05-13 |
| 12 | — | 12.7 | 2021-05-13 |
| 13 | — | 13.3 | 2021-05-13 |
| 9.6 | — | 9.6.22 | 2021-05-13 |
CVSS 3.0
| Overall Score | 6.5 |
|---|
| Component | core server |
|---|
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
|---|
First published: 2021-05-13
Original security advisory · JSON · All advisories