{"id":"CVE-2023-5869","year":2023,"sequence":5869,"component":"core server","score":8.8,"cvss_version":"3.0","vector":"AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","first_published":"2023-11-09","source_url":"https://www.postgresql.org/support/security/CVE-2023-5869/","facts":{"affected":{"11":"11","12":"12","13":"13","14":"14","15":"15","16":"16"},"component":"core server","cvss_version":"3.0","description_en":"While modifying certain SQL array values, missing overflow checks let authenticated database users write arbitrary bytes to a memory area that facilitates arbitrary code execution. Missing overflow checks also let authenticated database users read a wide area of server memory. The CVE-2021-32027 fix covered some attacks of this description, but it missed others.\n\nThe PostgreSQL project thanks Pedro Gallegos for reporting this problem.","first_published":"2023-11-09","fixed":{"11":"11.22","12":"12.17","13":"13.13","14":"14.10","15":"15.5","16":"16.1"},"id":"CVE-2023-5869","introduced":{},"published":{"11":"2023-11-09","12":"2023-11-09","13":"2023-11-09","14":"2023-11-09","15":"2023-11-09","16":"2023-11-09"},"score":8.8,"title":"Buffer overrun from integer overflow in array modification","url":"https://www.postgresql.org/support/security/CVE-2023-5869/","vector":"AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"zh-Hans","title":"数组修改中的整数溢出会导致缓冲区越界","description":"数组修改中的整数溢出会导致缓冲区越界","details":null,"format":"markdown","provenance":{"identity":"immutable_cve_code","sources":[{"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"component":"core server","cve":"2023-5869","cvenumber":202305869,"description":"数组修改中的整数溢出会导致缓冲区越界","details":null,"detailslink":"https://access.redhat.com/security/cve/CVE-2023-5869","id":23,"legacyscore":"","newspost_id":null,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"source":"center","source_id":23,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"},{"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"component":"core server","cve":"2023-5869","cvenumber":202305869,"description":"数组修改中的整数溢出会导致缓冲区越界","details":null,"detailslink":"https://access.redhat.com/security/cve/CVE-2023-5869","id":23,"legacyscore":"","newspost_id":null,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"source":"pgweb","source_id":23,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"}]},"text_hash":"a5068b881726936914938e1a6d39e62a64a32cfaaef2e24e149e161d20bdc92b"},"locales":["en","zh-Hans"],"fixes":[{"major":"11","fixed_version":"11.22","introduced":null,"published_date":"2023-11-09","facts":{"fixed":"11.22","introduced":null,"published":"2023-11-09"}},{"major":"12","fixed_version":"12.17","introduced":null,"published_date":"2023-11-09","facts":{"fixed":"12.17","introduced":null,"published":"2023-11-09"}},{"major":"13","fixed_version":"13.13","introduced":null,"published_date":"2023-11-09","facts":{"fixed":"13.13","introduced":null,"published":"2023-11-09"}},{"major":"14","fixed_version":"14.10","introduced":null,"published_date":"2023-11-09","facts":{"fixed":"14.10","introduced":null,"published":"2023-11-09"}},{"major":"15","fixed_version":"15.5","introduced":null,"published_date":"2023-11-09","facts":{"fixed":"15.5","introduced":null,"published":"2023-11-09"}},{"major":"16","fixed_version":"16.1","introduced":null,"published_date":"2023-11-09","facts":{"fixed":"16.1","introduced":null,"published":"2023-11-09"}}],"legacy":[{"source":"center","source_id":23,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":23,"cve":"2023-5869","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","details":null,"component":"core server","cvenumber":202305869,"description":"数组修改中的整数溢出会导致缓冲区越界","detailslink":"https://access.redhat.com/security/cve/CVE-2023-5869","legacyscore":"","newspost_id":null},"fixes":[{"source_id":83,"source_version_id":29,"major":"16","fixed_minor":1,"raw":{"id":83,"patch_id":23,"version_id":29,"fixed_minor":1},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":84,"source_version_id":28,"major":"15","fixed_minor":5,"raw":{"id":84,"patch_id":23,"version_id":28,"fixed_minor":5},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":85,"source_version_id":27,"major":"14","fixed_minor":10,"raw":{"id":85,"patch_id":23,"version_id":27,"fixed_minor":10},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]},{"source":"pgweb","source_id":23,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":23,"cve":"2023-5869","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","details":null,"component":"core server","cvenumber":202305869,"description":"数组修改中的整数溢出会导致缓冲区越界","detailslink":"https://access.redhat.com/security/cve/CVE-2023-5869","legacyscore":"","newspost_id":null},"fixes":[{"source_id":83,"source_version_id":29,"major":"16","fixed_minor":1,"raw":{"id":83,"patch_id":23,"version_id":29,"fixed_minor":1},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":84,"source_version_id":28,"major":"15","fixed_minor":5,"raw":{"id":84,"patch_id":23,"version_id":28,"fixed_minor":5},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":85,"source_version_id":27,"major":"14","fixed_minor":10,"raw":{"id":85,"patch_id":23,"version_id":27,"fixed_minor":10},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]}]}
