目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1310

100%

CVE-2023-5869— PostgreSQL 安全漏洞

CVSS 8.8 · High EPSS 4.32% · P90
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2023-5869 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Postgresql: buffer overrun from integer overflow in array modification
来源: 美国国家漏洞数据库 NVD
Vulnerability Description
A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data. This enables the execution of arbitrary code on the target system, allowing users to write arbitrary bytes to memory and extensively read the server's memory.
来源: 美国国家漏洞数据库 NVD
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
来源: 美国国家漏洞数据库 NVD
Vulnerability Type
整数溢出或超界折返
来源: 美国国家漏洞数据库 NVD
Vulnerability Title
PostgreSQL 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
PostgreSQL是PostgreSQL组织的一套自由的对象关系型数据库管理系统。该系统支持大部分SQL标准并且提供了许多其他特性,例如外键、触发器、视图等。 PostgreSQL存在安全漏洞,该漏洞源于array modification存在整数溢出漏洞。受影响的产品和版本:PostgreSQL 16.1之前的16版本,15.5之前的15版本,14.10之前的14版本,13.13之前的13版本,12.17之前的12版本,11.22之前的11版本。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
Red HatRed Hat Advanced Cluster Security 4.2 4.2.4-6 ~ * cpe:/a:redhat:advanced_cluster_security:4.2::el8
Red HatRed Hat Advanced Cluster Security 4.2 4.2.4-6 ~ * cpe:/a:redhat:advanced_cluster_security:4.2::el8
Red HatRed Hat Advanced Cluster Security 4.2 4.2.4-7 ~ * cpe:/a:redhat:advanced_cluster_security:4.2::el8
Red HatRed Hat Advanced Cluster Security 4.2 4.2.4-6 ~ * cpe:/a:redhat:advanced_cluster_security:4.2::el8
Red HatRed Hat Advanced Cluster Security 4.2 4.2.4-7 ~ * cpe:/a:redhat:advanced_cluster_security:4.2::el8
Red HatRed Hat Enterprise Linux 7 0:9.2.24-9.el7_9 ~ * cpe:/o:redhat:enterprise_linux:7::server
Red HatRed Hat Enterprise Linux 8 8090020231114113712.a75119d5 ~ * cpe:/a:redhat:enterprise_linux:8::appstream
Red HatRed Hat Enterprise Linux 8 8090020231128173330.a75119d5 ~ * cpe:/a:redhat:enterprise_linux:8::appstream
Red HatRed Hat Enterprise Linux 8 8090020231201202407.a75119d5 ~ * cpe:/a:redhat:enterprise_linux:8::appstream
Red HatRed Hat Enterprise Linux 8 8090020231114113548.a75119d5 ~ * cpe:/a:redhat:enterprise_linux:8::appstream
Red HatRed Hat Enterprise Linux 8.1 Update Services for SAP Solutions 8010020231130170510.c27ad7f8 ~ * cpe:/a:redhat:rhel_e4s:8.1::appstream
Red HatRed Hat Enterprise Linux 8.2 Advanced Update Support 8020020231128165246.4cda2c84 ~ * cpe:/a:redhat:rhel_e4s:8.2::appstream
Red HatRed Hat Enterprise Linux 8.2 Advanced Update Support 8020020231201202149.4cda2c84 ~ * cpe:/a:redhat:rhel_e4s:8.2::appstream
Red HatRed Hat Enterprise Linux 8.2 Telecommunications Update Service 8020020231128165246.4cda2c84 ~ * cpe:/a:redhat:rhel_e4s:8.2::appstream
Red HatRed Hat Enterprise Linux 8.2 Telecommunications Update Service 8020020231201202149.4cda2c84 ~ * cpe:/a:redhat:rhel_e4s:8.2::appstream
Red HatRed Hat Enterprise Linux 8.2 Update Services for SAP Solutions 8020020231128165246.4cda2c84 ~ * cpe:/a:redhat:rhel_e4s:8.2::appstream
Red HatRed Hat Enterprise Linux 8.2 Update Services for SAP Solutions 8020020231201202149.4cda2c84 ~ * cpe:/a:redhat:rhel_e4s:8.2::appstream
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 8040020231127153301.522a0ee4 ~ * cpe:/a:redhat:rhel_e4s:8.4::appstream
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 8040020231127154806.522a0ee4 ~ * cpe:/a:redhat:rhel_e4s:8.4::appstream
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 8040020231127142440.522a0ee4 ~ * cpe:/a:redhat:rhel_e4s:8.4::appstream
Red HatRed Hat Enterprise Linux 8.4 Telecommunications Update Service 8040020231127153301.522a0ee4 ~ * cpe:/a:redhat:rhel_e4s:8.4::appstream
Red HatRed Hat Enterprise Linux 8.4 Telecommunications Update Service 8040020231127154806.522a0ee4 ~ * cpe:/a:redhat:rhel_e4s:8.4::appstream
Red HatRed Hat Enterprise Linux 8.4 Telecommunications Update Service 8040020231127142440.522a0ee4 ~ * cpe:/a:redhat:rhel_e4s:8.4::appstream
Red HatRed Hat Enterprise Linux 8.4 Update Services for SAP Solutions 8040020231127153301.522a0ee4 ~ * cpe:/a:redhat:rhel_e4s:8.4::appstream
Red HatRed Hat Enterprise Linux 8.4 Update Services for SAP Solutions 8040020231127154806.522a0ee4 ~ * cpe:/a:redhat:rhel_e4s:8.4::appstream
Red HatRed Hat Enterprise Linux 8.4 Update Services for SAP Solutions 8040020231127142440.522a0ee4 ~ * cpe:/a:redhat:rhel_e4s:8.4::appstream
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support 8060020231114115246.ad008a3a ~ * cpe:/a:redhat:rhel_eus:8.6::appstream
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support 8060020231128165328.ad008a3a ~ * cpe:/a:redhat:rhel_eus:8.6::appstream
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support 8060020231201202249.ad008a3a ~ * cpe:/a:redhat:rhel_eus:8.6::appstream
Red HatRed Hat Enterprise Linux 8.8 Extended Update Support 8080020231114105206.63b34585 ~ * cpe:/a:redhat:rhel_eus:8.8::appstream
Red HatRed Hat Enterprise Linux 8.8 Extended Update Support 8080020231128165335.63b34585 ~ * cpe:/a:redhat:rhel_eus:8.8::appstream
Red HatRed Hat Enterprise Linux 8.8 Extended Update Support 8080020231201202316.63b34585 ~ * cpe:/a:redhat:rhel_eus:8.8::appstream
Red HatRed Hat Enterprise Linux 8.8 Extended Update Support 8080020231113134015.63b34585 ~ * cpe:/a:redhat:rhel_eus:8.8::appstream
Red HatRed Hat Enterprise Linux 9 0:13.13-1.el9_3 ~ * cpe:/a:redhat:enterprise_linux:9::crb
Red HatRed Hat Enterprise Linux 9 9030020231120082734.rhel9 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red HatRed Hat Enterprise Linux 9.0 Extended Update Support 0:13.13-1.el9_0 ~ * cpe:/a:redhat:rhel_eus:9.0::appstream
Red HatRed Hat Enterprise Linux 9.2 Extended Update Support 0:13.13-1.el9_2 ~ * cpe:/a:redhat:rhel_eus:9.2::crb
Red HatRed Hat Enterprise Linux 9.2 Extended Update Support 9020020231115020618.rhel9 ~ * cpe:/a:redhat:rhel_eus:9.2::appstream
Red HatRed Hat Software Collections for Red Hat Enterprise Linux 7 0:12.17-1.el7 ~ * cpe:/a:redhat:rhel_software_collections:3::el7
Red HatRed Hat Software Collections for Red Hat Enterprise Linux 7 0:10.23-2.el7 ~ * cpe:/a:redhat:rhel_software_collections:3::el7
Red HatRed Hat Software Collections for Red Hat Enterprise Linux 7 0:13.13-1.el7 ~ * cpe:/a:redhat:rhel_software_collections:3::el7
Red HatRHACS-3.74-RHEL-8 3.74.8-9 ~ * cpe:/a:redhat:advanced_cluster_security:3.74::el8
Red HatRHACS-3.74-RHEL-8 3.74.8-9 ~ * cpe:/a:redhat:advanced_cluster_security:3.74::el8
Red HatRHACS-3.74-RHEL-8 3.74.8-7 ~ * cpe:/a:redhat:advanced_cluster_security:3.74::el8
Red HatRHACS-3.74-RHEL-8 3.74.8-9 ~ * cpe:/a:redhat:advanced_cluster_security:3.74::el8
Red HatRHACS-3.74-RHEL-8 3.74.8-9 ~ * cpe:/a:redhat:advanced_cluster_security:3.74::el8
Red HatRHACS-4.1-RHEL-8 4.1.6-6 ~ * cpe:/a:redhat:advanced_cluster_security:4.1::el8
Red HatRHACS-4.1-RHEL-8 4.1.6-6 ~ * cpe:/a:redhat:advanced_cluster_security:4.1::el8
Red HatRHACS-4.1-RHEL-8 4.1.6-6 ~ * cpe:/a:redhat:advanced_cluster_security:4.1::el8
Red HatRHACS-4.1-RHEL-8 4.1.6-6 ~ * cpe:/a:redhat:advanced_cluster_security:4.1::el8
Red HatRHACS-4.1-RHEL-8 4.1.6-6 ~ * cpe:/a:redhat:advanced_cluster_security:4.1::el8
Red HatRed Hat Enterprise Linux 6-cpe:/o:redhat:enterprise_linux:6
Red HatRed Hat Enterprise Linux 8-cpe:/o:redhat:enterprise_linux:8
Red HatRed Hat Enterprise Linux 9-cpe:/o:redhat:enterprise_linux:9

二、漏洞 CVE-2023-5869 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2023-5869 的情报信息

登录查看更多情报信息。

CVE-2023-5869 厂商安全公告 (31)

CVE-2023-5869 其他参考 (1)

同批安全公告 · Red Hat · 2023-12-10 · 共 3 条

CVE-2023-58684.3 MEDIUMPostgreSQL 安全漏洞
CVE-2023-58702.2 LOWPostgreSQL 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2023-5869

暂无评论


发表评论