Out-of-bounds read was discovered in YDB server. An attacker could construct a query with insert statement that would allow him to read sensitive information from other memory locations or cause a crash.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://ydb.tech/ru/docs/security-changelog#28-11-2022 | vendor advisory |