Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Bulk Dictionary Decompression Negative Index
Vulnerability Description
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authenticated attackers to cause query-result integrity failures or backend crashes by supplying a crafted Simple8b selector-11 value, which is stored in the signed int16 Arrow dictionary-index type and bypasses index validation checks in bulk text dictionary decompression. Attackers with direct DML access to a non-frozen physical compressed hypertable relation can trigger an out-of-bounds read before the base of the live offsets array through the VectorAgg single-text hashing strategy, resulting in incorrect aggregation output, backend SIGSEGV, or PostgreSQL crash recovery depending on build configuration.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Vulnerability Type
对数组索引的验证不恰当
Vulnerability Title
TimescaleDB 缓冲区错误漏洞
Vulnerability Description
TimescaleDB是TimescaleDB公司的一款提供时序数据高效处理的数据库扩展。 TimescaleDB 2.29.1及之前版本存在安全漏洞,该漏洞源于提供特制的Simple8b selector-11值,该值存储在signed int16 Arrow字典索引类型中,绕过批量文本字典解压的索引验证检查,可能导致已认证攻击者触发越界读取,造成查询结果完整性失败或后端崩溃。
CVSS Information
N/A
Vulnerability Type
N/A