Information disclosure in PostgreSQL - CVE-2021-3393

 

Information disclosure in PostgreSQL - CVE-2021-3393

Published: February 11, 2021


Vulnerability identifier: #VU50655
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3393
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in the error message. A remote user having an UPDATE privilege on a partitioned table but lacking the SELECT privilege on some column may be able to acquire denied-column values from an error message. This vulnerability is similar to #VU30418.


Affected software

PostgreSQL
Arch Linux
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
Ubuntu
Red Hat Software Collections
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
postgresql (Alpine package)
rh-postgresql12-postgresql (Red Hat package)
postgres-decoderbufs
pgaudit
postgresql-12 (Ubuntu package)
postgresql12
postgresql12-debuginfo
postgresql12-contrib
postgresql12-contrib-debuginfo
postgresql12-debugsource
postgresql12-devel
postgresql12-devel-debuginfo
postgresql12-plperl
postgresql12-plperl-debuginfo
postgresql12-plpython
postgresql12-plpython-debuginfo
postgresql12-pltcl
postgresql12-pltcl-debuginfo
postgresql12-server
postgresql12-server-debuginfo
postgresql12-server-devel
postgresql12-server-devel-debuginfo
postgresql12-docs
libpq5-32bit
libpq5-32bit-debuginfo
libpq5
libecpg6-debuginfo
libecpg6
libpq5-debuginfo
postgresql
postgresql-test-rpm-macros
postgresql-contrib
postgresql-docs
postgresql-plperl
postgresql-plpython3
postgresql-pltcl
postgresql-server
postgresql-server-devel
postgresql-static
postgresql-test
postgresql-upgrade
postgresql-upgrade-devel
IBM Security Verify Access

How to mitigate CVE-2021-3393

Install updates from vendor's website.

PostgreSQL - addressed in versions 11.11, 12.6, 13.2
postgresql (Alpine package) - addressed in versions 11.11-r0, 12.6-r0
rh-postgresql12-postgresql (Red Hat package) - update to 12.7-1.el7
postgres-decoderbufs - update to 0.10.0-2
pgaudit - update to 1.4.0-6
postgresql-12 (Ubuntu package) - addressed in versions 12.6-0ubuntu0.20.04.1, 12.6-0ubuntu0.20.10.1
postgresql12 - addressed in versions 12.6-3.21.4, 12.7-3.15.3
postgresql12-debuginfo - addressed in versions 12.6-3.21.4, 12.7-3.15.3
postgresql12-contrib - addressed in versions 12.6-3.21.4, 12.7-3.15.3
postgresql12-contrib-debuginfo - addressed in versions 12.6-3.21.4, 12.7-3.15.3
postgresql12-debugsource - addressed in versions 12.6-3.21.4, 12.7-3.15.3
postgresql12-devel - addressed in versions 12.6-3.21.4, 12.7-3.15.3
postgresql12-devel-debuginfo - addressed in versions 12.6-3.21.4, 12.7-3.15.3
postgresql12-plperl - addressed in versions 12.6-3.21.4, 12.7-3.15.3
postgresql12-plperl-debuginfo - addressed in versions 12.6-3.21.4, 12.7-3.15.3
postgresql12-plpython - addressed in versions 12.6-3.21.4, 12.7-3.15.3
postgresql12-plpython-debuginfo - addressed in versions 12.6-3.21.4, 12.7-3.15.3
postgresql12-pltcl - addressed in versions 12.6-3.21.4, 12.7-3.15.3
postgresql12-pltcl-debuginfo - addressed in versions 12.6-3.21.4, 12.7-3.15.3
postgresql12-server - addressed in versions 12.6-3.21.4, 12.7-3.15.3
postgresql12-server-debuginfo - addressed in versions 12.6-3.21.4, 12.7-3.15.3
postgresql12-server-devel - addressed in versions 12.6-3.21.4, 12.7-3.15.3
postgresql12-server-devel-debuginfo - addressed in versions 12.6-3.21.4, 12.7-3.15.3
postgresql12-docs - addressed in versions 12.6-3.21.4, 12.7-3.15.3
libpq5-32bit - update to 12.6-3.21.4
libpq5-32bit-debuginfo - update to 12.6-3.21.4
libpq5 - update to 12.6-3.21.4
libecpg6-debuginfo - update to 12.6-3.21.4
libecpg6 - update to 12.6-3.21.4
libpq5-debuginfo - update to 12.6-3.21.4
postgresql - update to 12.7-1
postgresql-test-rpm-macros - update to 12.7-1
postgresql-contrib - update to 12.7-1
postgresql-docs - update to 12.7-1
postgresql-plperl - update to 12.7-1
postgresql-plpython3 - update to 12.7-1
postgresql-pltcl - update to 12.7-1
postgresql-server - update to 12.7-1
postgresql-server-devel - update to 12.7-1
postgresql-static - update to 12.7-1
postgresql-test - update to 12.7-1
postgresql-upgrade - update to 12.7-1
postgresql-upgrade-devel - update to 12.7-1

External References

Related Security Bulletins