ALPINE-CVE-2018-1052 PUBLISHED CVSS 6.5 MEDIUM

Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticated attacker to read arbitrary bytes of server memory via purpose-crafted insert to a partitioned table.

Risk Scores

CVSS v3.0
6.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Alpine:v3.18postgresql150, 0, 0
Alpine:v3.16postgresql149.4.1-r3, 9.4.1-r2, 9.4.1-r1
Alpine:v3.15postgresql149.1.2-r0, 8.4.3-r0, 8.4.3-r1
Alpine:v3.19postgresql150, 0, 0
Alpine:v3.17postgresql149.1.2-r0, 9.1.1-r2, 9.1.1-r1
Alpine:v3.18postgresql149.6.0-r0, 9.5.3-r1, 9.5.3-r0
Alpine:v3.9postgresql9.3.4-r0, 9.5.2-r0, 9.5.1-r0
Alpine:v3.11postgresql9.6.2-r4, 8.3.7-r1, 8.3.5-r0
Alpine:v3.20postgresql150, 0, 0
Alpine:v3.8postgresql9.2.0-r1, 0, 10.0-r0
Alpine:v3.7postgresql0, 9.6.5-r1, 9.6.5-r0
Alpine:v3.13postgresql9.6.4-r0, 9.6.5-r1, 9.6.5-r0
Alpine:v3.12postgresql9.5.3-r0, 9.6.4-r1, 9.6.4-r0
Alpine:v3.17postgresql150, 0, 0
Alpine:v3.10postgresql10.0-r1, 9.6.5-r1, 9.6.5-r0
Alpine:v3.14postgresql9.5.4-r0, 0, 10.0-r0

Timeline

References

Open in Interactive Console →