ZeroHour

CVE-2023-5870

CVSS 3.1
4.4 medium
EPSS
3%p84
Published
()
Modified
Description

A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

Vendors
postgresqlredhat
Products
postgresql, codeready linux builder eus, codeready linux builder eus for power little endian eus, codeready linux builder for arm64 eus, codeready linux builder for ibm z systems eus, codeready linux builder for power little endian eus, software collections, enterprise linux, enterprise linux eus, enterprise linux for arm 64, enterprise linux for ibm z systems, enterprise linux for ibm z systems eus
Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.