We found results for “”
WS-2019-0603
Good to know:
Date: October 7, 2019
In PostgreSQL, versions 9.5 prior to REL9_5_20, 9.6 prior to REL9_6_16, 10 prior to REL_10_11, 11 prior to REL_11_6, 12 prior to REL_12_1, are vulnerable to uncontrolled resource consumption, due to a missing if maximum child processes are running when creating a new bgworker. When the postmaster’s child-process arrays are temporarily full, a malicious client can spawn a new bgworker process and crash the postmaster.
Language: C
Severity Score
Related Resources (8)
Severity Score
Weakness Type (CWE)
Uncontrolled Resource Consumption ('Resource Exhaustion')
CWE-400Top Fix
Upgrade Version
Upgrade to version REL9_5_20, REL9_6_16, REL_10_11, REL_11_6, REL_12_1, REL_13_0
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | NONE |
Availability (A): | HIGH |