In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.
Version | Score | Severity | Vector String |
---|---|---|---|
3.1 | 3.7 | Low | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Product | Vendor | Version |
---|---|---|
postgresql | n/a | n/a |