Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticated attacker to read arbitrary bytes of server memory via purpose-crafted insert to a partitioned table.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.postgresql.org/about/news/1829/ | release notes patch vendor advisory |
http://www.securityfocus.com/bid/102987 | vdb entry third party advisory |