CVE-2018-1052: Infoleak
Published Feb 9, 2018
·Updated
Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticated attacker to read arbitrary bytes of server memory via purpose-crafted insert to a partitioned table.
Affected Software
2 affected components
PostgreSQL postgresql=10.0
PostgreSQL postgresql=10.1
Remediation
Patch Available
Event History
Feb 9, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-1052?
CVE-2018-1052 is a memory disclosure vulnerability in table partitioning in PostgreSQL 10.x before 10.2.
2
How does CVE-2018-1052 impact PostgreSQL?
CVE-2018-1052 allows an authenticated attacker to read arbitrary bytes of server memory via purpose-crafted insert to a partitioned table in PostgreSQL 10.x before 10.2.
3
What is the severity of CVE-2018-1052?
The severity of CVE-2018-1052 is medium with a CVSS score of 6.5.
4
Which software versions are affected by CVE-2018-1052?
PostgreSQL 10.0 and 10.1 are affected by CVE-2018-1052.
5
How can I fix CVE-2018-1052?
To fix CVE-2018-1052, upgrade to PostgreSQL 10.2 or later.