![]() |
|
Message-ID: <38844bb7-2fb5-43fc-bf12-3808a35ba657@oracle.com> Date: Fri, 9 May 2025 08:50:46 -0700 From: Alan Coopersmith <alan.coopersmith@...cle.com> To: oss-security@...ts.openwall.com Subject: CVE-2025-4207: PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation https://www.postgresql.org/about/news/postgresql-175-169-1513-1418-and-1321-released-3072/ announces the release of PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21, all of which include a fix for: CVE-2025-4207: PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation CVSS v3.1 Base Score: 5.9 Supported, Vulnerable Versions: 13 - 17. A buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected. -- -Alan Coopersmith- alan.coopersmith@...cle.com Oracle Solaris Engineering - https://blogs.oracle.com/solaris
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.