Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Commitdfb5ad7

Browse files
committed
Last-minute updates for release notes.
Security:CVE-2022-41862
1 parent28ac6d0 commitdfb5ad7

File tree

1 file changed

+29
-0
lines changed

1 file changed

+29
-0
lines changed

‎doc/src/sgml/release-14.sgml

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -35,6 +35,35 @@
3535

3636
<listitem>
3737
<!--
38+
Author: Michael Paquier <michael@paquier.xyz>
39+
Branch: master [71c37797d] 2023-02-06 11:20:07 +0900
40+
Branch: REL_15_STABLE [715c345dd] 2023-02-06 11:20:20 +0900
41+
Branch: REL_14_STABLE [626f2c1d6] 2023-02-06 11:20:23 +0900
42+
Branch: REL_13_STABLE [45a945ee9] 2023-02-06 11:20:27 +0900
43+
Branch: REL_12_STABLE [3f7342671] 2023-02-06 11:20:31 +0900
44+
-->
45+
<para>
46+
<application>libpq</application> can leak memory contents after
47+
GSSAPI transport encryption initiation fails (Jacob Champion)
48+
</para>
49+
50+
<para>
51+
A modified server, or an unauthenticated man-in-the-middle, can
52+
send a not-zero-terminated error message during setup of GSSAPI
53+
(Kerberos) transport encryption. <application>libpq</application>
54+
will then copy that string, as well as following bytes in
55+
application memory up to the next zero byte, to its error report.
56+
Depending on what the calling application does with the error
57+
report, this could result in disclosure of application memory
58+
contents. There is also a small probability of a crash due to
59+
reading beyond the end of memory. Fix by properly zero-terminating
60+
the server message.
61+
(CVE-2022-41862)
62+
</para>
63+
</listitem>
64+
65+
<listitem>
66+
<!--
3867
Author: Tom Lane <tgl@sss.pgh.pa.us>
3968
Branch: master [3f7836ff6] 2023-01-05 14:12:17 -0500
4069
Branch: REL_15_STABLE [3706cc97a] 2023-01-05 14:12:17 -0500

0 commit comments

Comments
 (0)

[8]ページ先頭

©2009-2025 Movatter.jp