SB2019051017 - Memory leak in postgresql (Alpine package)
Published: May 10, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2019-10129)
The vulnerability allows a remote attacker to read parts of system memory.
The vulnerability exists due memory leak when processing INSERT queries. A remote authenticated user can execute a specially crafted INSERT statement to a partitioned table and read parts of memory.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=2b95c8929982c3ff86b48ffe921cf9ddff6aeebd
- https://git.alpinelinux.org/aports/commit/?id=5f580c412de14f7329bf77293a1c8bbce8a74d48
- https://git.alpinelinux.org/aports/commit/?id=f0bd10f20b351a67282e252cb17bc8a175732c8b
- https://git.alpinelinux.org/aports/commit/?id=6a033ac469647786c8b26d97bc6fad0fa1d35eac
- https://git.alpinelinux.org/aports/commit/?id=dcb2fb74df0bbd2b96eca88070ab7e10ab8a38e1
- https://git.alpinelinux.org/aports/commit/?id=0ce51efa7e896396543355530cdf113bcb648bc0
- https://git.alpinelinux.org/aports/commit/?id=2b1e41ba04b72d78488d8ed2719c535d19313255
- https://git.alpinelinux.org/aports/commit/?id=3c20033f75ab5c8b506ad5e4acb3438626aff953
- https://git.alpinelinux.org/aports/commit/?id=7cf139bac41c8f2e1885d5f99334daeaeb059ac3