{"id":"CVE-2022-41862","year":2022,"sequence":41862,"component":"client","score":3.7,"cvss_version":"3.0","vector":"AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","first_published":"2023-02-09","source_url":"https://www.postgresql.org/support/security/CVE-2022-41862/","facts":{"affected":{"12":"12","13":"13","14":"14","15":"15"},"component":"client","cvss_version":"3.0","description_en":"A modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. When a libpq client application has a Kerberos credential cache and doesn't explicitly disable option gssencmode , a server can cause libpq to over-read and report an error message containing uninitialized bytes from and following its receive buffer. If libpq's caller somehow makes that message accessible to the attacker, this achieves a disclosure of the over-read bytes. We have not confirmed or ruled out viability of attacks that arrange for a crash or for presence of notable, confidential information in disclosed bytes.\n\nThe PostgreSQL project thanks Jacob Champion for reporting this problem.","first_published":"2023-02-09","fixed":{"12":"12.14","13":"13.10","14":"14.7","15":"15.2"},"id":"CVE-2022-41862","introduced":{},"published":{"12":"2023-02-09","13":"2023-02-09","14":"2023-02-09","15":"2023-02-09"},"score":3.7,"title":"Client memory disclosure when connecting, with Kerberos, to modified server","url":"https://www.postgresql.org/support/security/CVE-2022-41862/","vector":"AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"zh-Hans","title":"使用 Kerberos 连接到被篡改的服务器时，客户端可能发生内存信息泄露","description":"使用 Kerberos 连接到被篡改的服务器时，客户端可能发生内存信息泄露","details":null,"format":"markdown","provenance":{"identity":"immutable_cve_code","sources":[{"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"component":"client","cve":"2022-41862","cvenumber":202241862,"description":"使用 Kerberos 连接到被篡改的服务器时，客户端可能发生内存信息泄露","details":null,"detailslink":"https://access.redhat.com/security/cve/CVE-2022-41862","id":27,"legacyscore":"","newspost_id":null,"public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"},"source":"center","source_id":27,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"},{"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"component":"client","cve":"2022-41862","cvenumber":202241862,"description":"使用 Kerberos 连接到被篡改的服务器时，客户端可能发生内存信息泄露","details":null,"detailslink":"https://access.redhat.com/security/cve/CVE-2022-41862","id":27,"legacyscore":"","newspost_id":null,"public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"},"source":"pgweb","source_id":27,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"}]},"text_hash":"8a6d15e67f96a7f221d7640f297768358a32367b45496c92b96e9d4be1125354"},"locales":["en","zh-Hans"],"fixes":[{"major":"12","fixed_version":"12.14","introduced":null,"published_date":"2023-02-09","facts":{"fixed":"12.14","introduced":null,"published":"2023-02-09"}},{"major":"13","fixed_version":"13.10","introduced":null,"published_date":"2023-02-09","facts":{"fixed":"13.10","introduced":null,"published":"2023-02-09"}},{"major":"14","fixed_version":"14.7","introduced":null,"published_date":"2023-02-09","facts":{"fixed":"14.7","introduced":null,"published":"2023-02-09"}},{"major":"15","fixed_version":"15.2","introduced":null,"published_date":"2023-02-09","facts":{"fixed":"15.2","introduced":null,"published":"2023-02-09"}}],"legacy":[{"source":"center","source_id":27,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":27,"cve":"2022-41862","public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","details":null,"component":"client","cvenumber":202241862,"description":"使用 Kerberos 连接到被篡改的服务器时，客户端可能发生内存信息泄露","detailslink":"https://access.redhat.com/security/cve/CVE-2022-41862","legacyscore":"","newspost_id":null},"fixes":[{"source_id":93,"source_version_id":28,"major":"15","fixed_minor":2,"raw":{"id":93,"patch_id":27,"version_id":28,"fixed_minor":2},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":94,"source_version_id":27,"major":"14","fixed_minor":7,"raw":{"id":94,"patch_id":27,"version_id":27,"fixed_minor":7},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]},{"source":"pgweb","source_id":27,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":27,"cve":"2022-41862","public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","details":null,"component":"client","cvenumber":202241862,"description":"使用 Kerberos 连接到被篡改的服务器时，客户端可能发生内存信息泄露","detailslink":"https://access.redhat.com/security/cve/CVE-2022-41862","legacyscore":"","newspost_id":null},"fixes":[{"source_id":93,"source_version_id":28,"major":"15","fixed_minor":2,"raw":{"id":93,"patch_id":27,"version_id":28,"fixed_minor":2},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":94,"source_version_id":27,"major":"14","fixed_minor":7,"raw":{"id":94,"patch_id":27,"version_id":27,"fixed_minor":7},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]}]}
