UBUNTU-CVE-2023-5870
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-5870
UBUNTU-CVE-2023-5870
Summary:
Details: A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.
References: https://ubuntu.com/security/CVE-2023-5870, https://www.postgresql.org/support/security/CVE-2023-5870/, https://www.postgresql.org/about/news/postgresql-161-155-1410-1313-1217-and-1122-released-2749/, https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=e082734c8e78e6622a0422e612a870278721e83f, https://ubuntu.com/security/notices/USN-6538-1, https://ubuntu.com/security/notices/USN-6570-1, https://ubuntu.com/security/notices/USN-6538-2, https://www.cve.org/CVERecord?id=CVE-2023-5870
Affected packages
Package
Name: postgresql-9.3
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
