Security Advisory

CVE-2022-41862

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-03-03 00:00:00
Last updated 2025-03-07 16:03:01
Assigner redhat
State PUBLISHED

Description

In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.