{"id":"CVE-2021-32027","year":2021,"sequence":32027,"component":"core server","score":6.5,"cvss_version":"3.0","vector":"AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","first_published":"2021-05-13","source_url":"https://www.postgresql.org/support/security/CVE-2021-32027/","facts":{"affected":{"10":"10","11":"11","12":"12","13":"13","9.6":"9.6"},"component":"core server","cvss_version":"3.0","description_en":"While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory.\n\nThe PostgreSQL project thanks Tom Lane for reporting this problem.","first_published":"2021-05-13","fixed":{"10":"10.17","11":"11.12","12":"12.7","13":"13.3","9.6":"9.6.22"},"id":"CVE-2021-32027","introduced":{},"published":{"10":"2021-05-13","11":"2021-05-13","12":"2021-05-13","13":"2021-05-13","9.6":"2021-05-13"},"score":6.5,"title":"Buffer overrun from integer overflow in array subscripting calculations","url":"https://www.postgresql.org/support/security/CVE-2021-32027/","vector":"AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"en","title":"Buffer overrun from integer overflow in array subscripting calculations","description":"While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory.\n\nThe PostgreSQL project thanks Tom Lane for reporting this problem.","details":null,"format":"plain","provenance":{"fetched_at":"2026-09-26T10:56:06+00:00","path":"compare/security.json","root":"source-data","sha256":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_archive_sha256":"8d8ad63581e1d27b3a0f995ded3feb81c265e38b2ac652eb22f022f52c2240ec","source_revision":"004bc292ee31c11f9a41ab007e9d8116bce29a71","source_url":"https://www.postgresql.org/support/security/"},"text_hash":"c1b4c58c4934e18e7d68411e4bcd53c19d02f21b2cbbed0034481f55dd5f6ebd"},"locales":["en"],"fixes":[{"major":"10","fixed_version":"10.17","introduced":null,"published_date":"2021-05-13","facts":{"fixed":"10.17","introduced":null,"published":"2021-05-13"}},{"major":"11","fixed_version":"11.12","introduced":null,"published_date":"2021-05-13","facts":{"fixed":"11.12","introduced":null,"published":"2021-05-13"}},{"major":"12","fixed_version":"12.7","introduced":null,"published_date":"2021-05-13","facts":{"fixed":"12.7","introduced":null,"published":"2021-05-13"}},{"major":"13","fixed_version":"13.3","introduced":null,"published_date":"2021-05-13","facts":{"fixed":"13.3","introduced":null,"published":"2021-05-13"}},{"major":"9.6","fixed_version":"9.6.22","introduced":null,"published_date":"2021-05-13","facts":{"fixed":"9.6.22","introduced":null,"published":"2021-05-13"}}],"legacy":[]}
