UBUNTU-CVE-2021-3393
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3393
UBUNTU-CVE-2021-3393
Summary:
Details: An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.
References: https://ubuntu.com/security/CVE-2021-3393, https://www.postgresql.org/about/news/postgresql-132-126-1111-1016-9621-and-9525-released-2165/, https://ubuntu.com/security/notices/USN-4735-1, https://www.cve.org/CVERecord?id=CVE-2021-3393
Affected packages
Package
Name: postgresql-12
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
