VulnerabilityModified
CVE-2018-1052
Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticated attacker to read arbitrary bytes of server memory via purpose-crafted insert to a partitioned table.
MEDIUM 6.5EPSS 1.79%
Does this matter?
Lower severity and a low EPSS score (1.79%). Track it; it rarely justifies an emergency change on its own.
Description
Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticated attacker to read arbitrary bytes of server memory via purpose-crafted insert to a partitioned table.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.79% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- postgresql/postgresql
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/102987Third Party Advisory, VDB Entry
- https://www.postgresql.org/about/news/1829/Patch, Release Notes, Vendor Advisory
- http://www.securityfocus.com/bid/102987Third Party Advisory, VDB Entry
- https://www.postgresql.org/about/news/1829/Patch, Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.