First published: Fri Feb 09 2018(Updated: )
Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticated attacker to read arbitrary bytes of server memory via purpose-crafted insert to a partitioned table.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
PostgreSQL PostgreSQL | =10.0 | |
PostgreSQL PostgreSQL | =10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1052 is a memory disclosure vulnerability in table partitioning in PostgreSQL 10.x before 10.2.
CVE-2018-1052 allows an authenticated attacker to read arbitrary bytes of server memory via purpose-crafted insert to a partitioned table in PostgreSQL 10.x before 10.2.
The severity of CVE-2018-1052 is medium with a CVSS score of 6.5.
PostgreSQL 10.0 and 10.1 are affected by CVE-2018-1052.
To fix CVE-2018-1052, upgrade to PostgreSQL 10.2 or later.