vulnerability

SUSE: CVE-2021-3393: SUSE Linux Security Advisory

Severity
4
CVSS
(AV:N/AC:M/Au:S/C:P/I:N/A:N)
Published
Feb 15, 2021
Added
Feb 23, 2021
Modified
Jun 13, 2023

Description

An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.

Solutions

suse-upgrade-libecpg6suse-upgrade-libecpg6-32bitsuse-upgrade-libpq5suse-upgrade-libpq5-32bitsuse-upgrade-postgresql12suse-upgrade-postgresql12-contribsuse-upgrade-postgresql12-develsuse-upgrade-postgresql12-docssuse-upgrade-postgresql12-llvmjitsuse-upgrade-postgresql12-plperlsuse-upgrade-postgresql12-plpythonsuse-upgrade-postgresql12-pltclsuse-upgrade-postgresql12-serversuse-upgrade-postgresql12-server-develsuse-upgrade-postgresql12-testsuse-upgrade-postgresql13suse-upgrade-postgresql13-contribsuse-upgrade-postgresql13-develsuse-upgrade-postgresql13-docssuse-upgrade-postgresql13-llvmjitsuse-upgrade-postgresql13-llvmjit-develsuse-upgrade-postgresql13-plperlsuse-upgrade-postgresql13-plpythonsuse-upgrade-postgresql13-pltclsuse-upgrade-postgresql13-serversuse-upgrade-postgresql13-server-develsuse-upgrade-postgresql13-testsuse-upgrade-postgresql14suse-upgrade-postgresql14-contribsuse-upgrade-postgresql14-develsuse-upgrade-postgresql14-docssuse-upgrade-postgresql14-llvmjitsuse-upgrade-postgresql14-llvmjit-develsuse-upgrade-postgresql14-plperlsuse-upgrade-postgresql14-plpythonsuse-upgrade-postgresql14-pltclsuse-upgrade-postgresql14-serversuse-upgrade-postgresql14-server-develsuse-upgrade-postgresql15
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.