CVE-2022-41862

LOW3.7EPSS 0.32%
Published: 3/3/2023Modified: 11/19/2025
Also known as:ALPINE-CVE-2022-41862

Description

In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.

Affected packages (7)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1LOW3.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

References (6)