|
|
Message-ID: <38844bb7-2fb5-43fc-bf12-3808a35ba657@oracle.com>
Date: Fri, 9 May 2025 08:50:46 -0700
From: Alan Coopersmith <alan.coopersmith@...cle.com>
To: oss-security@...ts.openwall.com
Subject: CVE-2025-4207: PostgreSQL GB18030 encoding validation
can read one byte past end of allocation for text that fails validation
https://www.postgresql.org/about/news/postgresql-175-169-1513-1418-and-1321-released-3072/
announces the release of PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21, all
of which include a fix for:
CVE-2025-4207: PostgreSQL GB18030 encoding validation can read one byte past end
of allocation for text that fails validation
CVSS v3.1 Base Score: 5.9
Supported, Vulnerable Versions: 13 - 17.
A buffer over-read in PostgreSQL GB18030 encoding validation allows a database
input provider to achieve temporary denial of service on platforms where a
1-byte over-read can elicit process termination.
This affects the database server and also libpq.
Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.
--
-Alan Coopersmith- alan.coopersmith@...cle.com
Oracle Solaris Engineering - https://blogs.oracle.com/solaris
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.