{"id":"CVE-2023-5868","year":2023,"sequence":5868,"component":"core server","score":4.3,"cvss_version":"3.0","vector":"AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","first_published":"2023-11-09","source_url":"https://www.postgresql.org/support/security/CVE-2023-5868/","facts":{"affected":{"11":"11","12":"12","13":"13","14":"14","15":"15","16":"16"},"component":"core server","cvss_version":"3.0","description_en":"Certain aggregate function calls receiving \"unknown\"-type arguments could disclose bytes of server memory from the end of the \"unknown\"-type value to the next zero byte. One typically gets an \"unknown\"-type value via a string literal having no type designation. We have not confirmed or ruled out viability of attacks that arrange for presence of notable, confidential information in disclosed bytes.\n\nThe PostgreSQL project thanks Jingzhou Fu for reporting this problem.","first_published":"2023-11-09","fixed":{"11":"11.22","12":"12.17","13":"13.13","14":"14.10","15":"15.5","16":"16.1"},"id":"CVE-2023-5868","introduced":{},"published":{"11":"2023-11-09","12":"2023-11-09","13":"2023-11-09","14":"2023-11-09","15":"2023-11-09","16":"2023-11-09"},"score":4.3,"title":"Memory disclosure in aggregate function calls","url":"https://www.postgresql.org/support/security/CVE-2023-5868/","vector":"AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"en","title":"Memory disclosure in aggregate function calls","description":"Certain aggregate function calls receiving \"unknown\"-type arguments could disclose bytes of server memory from the end of the \"unknown\"-type value to the next zero byte. One typically gets an \"unknown\"-type value via a string literal having no type designation. We have not confirmed or ruled out viability of attacks that arrange for presence of notable, confidential information in disclosed bytes.\n\nThe PostgreSQL project thanks Jingzhou Fu for reporting this problem.","details":null,"format":"plain","provenance":{"fetched_at":"2026-09-26T10:56:06+00:00","path":"compare/security.json","root":"source-data","sha256":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_archive_sha256":"8d8ad63581e1d27b3a0f995ded3feb81c265e38b2ac652eb22f022f52c2240ec","source_revision":"004bc292ee31c11f9a41ab007e9d8116bce29a71","source_url":"https://www.postgresql.org/support/security/"},"text_hash":"159138d96a27ab6f15894f56d7966e9ccc8c73c7b2172b528e0735404a8eafba"},"locales":["en","zh-Hans"],"fixes":[{"major":"11","fixed_version":"11.22","introduced":null,"published_date":"2023-11-09","facts":{"fixed":"11.22","introduced":null,"published":"2023-11-09"}},{"major":"12","fixed_version":"12.17","introduced":null,"published_date":"2023-11-09","facts":{"fixed":"12.17","introduced":null,"published":"2023-11-09"}},{"major":"13","fixed_version":"13.13","introduced":null,"published_date":"2023-11-09","facts":{"fixed":"13.13","introduced":null,"published":"2023-11-09"}},{"major":"14","fixed_version":"14.10","introduced":null,"published_date":"2023-11-09","facts":{"fixed":"14.10","introduced":null,"published":"2023-11-09"}},{"major":"15","fixed_version":"15.5","introduced":null,"published_date":"2023-11-09","facts":{"fixed":"15.5","introduced":null,"published":"2023-11-09"}},{"major":"16","fixed_version":"16.1","introduced":null,"published_date":"2023-11-09","facts":{"fixed":"16.1","introduced":null,"published":"2023-11-09"}}],"legacy":[{"source":"center","source_id":24,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":24,"cve":"2023-5868","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","details":null,"component":"core server","cvenumber":202305868,"description":"聚合函数调用中存在内存信息泄露","detailslink":"https://access.redhat.com/security/cve/CVE-2023-5868","legacyscore":"","newspost_id":null},"fixes":[{"source_id":86,"source_version_id":29,"major":"16","fixed_minor":1,"raw":{"id":86,"patch_id":24,"version_id":29,"fixed_minor":1},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":87,"source_version_id":28,"major":"15","fixed_minor":5,"raw":{"id":87,"patch_id":24,"version_id":28,"fixed_minor":5},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":88,"source_version_id":27,"major":"14","fixed_minor":10,"raw":{"id":88,"patch_id":24,"version_id":27,"fixed_minor":10},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]},{"source":"pgweb","source_id":24,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":24,"cve":"2023-5868","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","details":null,"component":"core server","cvenumber":202305868,"description":"聚合函数调用中存在内存信息泄露","detailslink":"https://access.redhat.com/security/cve/CVE-2023-5868","legacyscore":"","newspost_id":null},"fixes":[{"source_id":86,"source_version_id":29,"major":"16","fixed_minor":1,"raw":{"id":86,"patch_id":24,"version_id":29,"fixed_minor":1},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":87,"source_version_id":28,"major":"15","fixed_minor":5,"raw":{"id":87,"patch_id":24,"version_id":28,"fixed_minor":5},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":88,"source_version_id":27,"major":"14","fixed_minor":10,"raw":{"id":88,"patch_id":24,"version_id":27,"fixed_minor":10},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]}]}
