SB2021022618 - Information disclosure in postgresql (Alpine package)
Published: February 26, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2021-3393)
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in the error message. A remote user having an UPDATE privilege on a partitioned table but lacking the
SELECT privilege on some column may be able to acquire denied-column values
from an error message. This vulnerability is similar to #VU30418.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=2ac5b2e57e4f1cab9571f0d467b1da99baa8c11b
- https://git.alpinelinux.org/aports/commit/?id=c729312a3e9d40ea50e135c021624c4a2edfafa0
- https://git.alpinelinux.org/aports/commit/?id=29681ecc8547bee9af8e9c4a2aa0c707717013b6
- https://git.alpinelinux.org/aports/commit/?id=e04ed3a2193bc362cadea9bb8b1911ea83e77b6a
- https://git.alpinelinux.org/aports/commit/?id=87ef3a18fd31dcdb5a100656f41792899105eb76
- https://git.alpinelinux.org/aports/commit/?id=de44e327d46ea44425f83cbf8c0d3368ecf74399