CVE-2023-5868
A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 2.79%
- CWE
- CWE-686
- Published
- 2023-12-10
- Last modified
- 2026-06-23
Affected products
- Red Hat Red Hat Advanced Cluster Security 4.2
- Red Hat Red Hat Advanced Cluster Security 4.2
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 8.2 Advanced Update Support
- Red Hat Red Hat Enterprise Linux 8.2 Telecommunications Update Service
- Red Hat Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
Weakness type
Related vulnerabilities
- CVE-2026-78422 — zbus_polkit: polkit authorization bypass via PID reuse due to incorrect D-Bus type for the subject UID
- CVE-2026-33783 — Junos OS Evolved: PTX Series: If SRTE tunnels provisioned via PCEP are present and specific gRPC queries are received evo-aftmand crashes
- CVE-2024-32632 — Printf arg type mismatch in ATCMD