A flaw was found in PostgreSQL that allows authenticated...
High severity
Unreviewed
Published
Dec 10, 2023
to the GitHub Advisory Database
•
Updated Sep 16, 2024
Description
Published by the National Vulnerability Database
Dec 10, 2023
Published to the GitHub Advisory Database
Dec 10, 2023
Last updated
Sep 16, 2024
A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data. This enables the execution of arbitrary code on the target system, allowing users to write arbitrary bytes to memory and extensively read the server's memory.
References