Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <38844bb7-2fb5-43fc-bf12-3808a35ba657@oracle.com>
Date: Fri, 9 May 2025 08:50:46 -0700
From: Alan Coopersmith <alan.coopersmith@...cle.com>
To: oss-security@...ts.openwall.com
Subject: CVE-2025-4207: PostgreSQL GB18030 encoding validation
 can read one byte past end of allocation for text that fails validation

https://www.postgresql.org/about/news/postgresql-175-169-1513-1418-and-1321-released-3072/
announces the release of PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21, all
of which include a fix for:

CVE-2025-4207: PostgreSQL GB18030 encoding validation can read one byte past end
  of allocation for text that fails validation

CVSS v3.1 Base Score: 5.9

Supported, Vulnerable Versions: 13 - 17.

A buffer over-read in PostgreSQL GB18030 encoding validation allows a database
input provider to achieve temporary denial of service on platforms where a
1-byte over-read can elicit process termination.

This affects the database server and also libpq.

Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.

-- 
         -Alan Coopersmith-                 alan.coopersmith@...cle.com
          Oracle Solaris Engineering - https://blogs.oracle.com/solaris

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.