NA

CVE-2023-39418

Published: 11/08/2023 Updated: 16/02/2024
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.

Vulnerable Product Search on Vulmon Subscribe to Product

postgresql postgresql

redhat enterprise linux 8.0

redhat enterprise linux 9.0

debian debian linux 12.0

Vendor Advisories

Several vulnerabilities have been discovered in the PostgreSQL database system CVE-2023-5868 Jingzhou Fu discovered a memory disclosure flaw in aggregate function calls CVE-2023-5869 Pedro Gallegos reported integer overflow flaws resulting in buffer overflows in the array modification functions CVE-2023-5870 Hemanth Sandrana ...
概述 Important: postgresql:15 security update 类型/严重性 Security Advisory: Important Red Hat Insights 补丁分析 识别并修复受此公告影响的系统。 查看受影响的系统 标题 An update for the postgresql:15 module is now available for Red Hat Enterprise Linux 92 Extended Update SupportRed Hat Product Sec ...
概述 Important: postgresql:15 security update 类型/严重性 Security Advisory: Important Red Hat Insights 补丁分析 识别并修复受此公告影响的系统。 查看受影响的系统 标题 An update for the postgresql:15 module is now available for Red Hat Enterprise Linux 88 Extended Update SupportRed Hat Product Sec ...
Synopsis Important: postgresql:15 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the postgresql:15 module is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated t ...
Synopsis Important: postgresql:15 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the postgresql:15 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated t ...
Description<!----> This CVE is under investigation by Red Hat Product Security ...
PostgreSQL 15 introduced the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT If UPDATE and SELECT policies forbid some row that INSERT policies do not forbid, a user could store such rows Subsequent consequences are application-dependent This affects only databases that have used CREATE PO ...