CVE-2021-32027
Summary
| CVE | CVE-2021-32027 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-01 14:15:00 UTC |
| Updated | 2023-11-07 03:35:00 UTC |
| Description | A flaw was found in postgresql in versions before 13.3, before 12.7, before 11.12, before 10.17 and before 9.6.22. While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CVE-2021-32027 PostgreSQL Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| PostgreSQL: CVE-2021-32027: Buffer overrun from integer overflow in array subscripting calculations |
MISC |
www.postgresql.org |
|
| 1956876 – (CVE-2021-32027) CVE-2021-32027 postgresql: Buffer overrun from integer overflow in array subscripting calculations |
MISC |
bugzilla.redhat.com |
|
| PostgreSQL: Multiple Vulnerabilities (GLSA 202211-04) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159265 Oracle Enterprise Linux Security Update for postgresql:9.6 (ELSA-2021-2360)
- 159266 Oracle Enterprise Linux Security Update for postgresql:10 (ELSA-2021-2361)
- 159268 Oracle Enterprise Linux Security Update for postgresql:12 (ELSA-2021-2372)
- 159269 Oracle Enterprise Linux Security Update for postgresql:13 (ELSA-2021-2375)
- 159275 Oracle Enterprise Linux Security Update for postgresql (ELSA-2021-2397)
- 159369 Oracle Enterprise Linux Security Update for rh-postgresql10-postgresql (ELSA-2021-9428)
- 178598 Debian Security Update for postgresql-9.6 (DLA 2662-1)
- 178617 Debian Security Update for postgresql-11 (DSA 4915-1)
- 180473 Debian Security Update for postgresql-13 (CVE-2021-32027)
- 198391 Ubuntu Security Notification for PostgreSQL vulnerabilities (USN-4972-1)
- 239382 Red Hat Update for postgresql:13 (RHSA-2021:2375)
- 239383 Red Hat Update for postgresql:12 (RHSA-2021:2372)
- 239389 Red Hat Update for postgresql:10 (RHSA-2021:2361)
- 239390 Red Hat Update for postgresql:9.6 (RHSA-2021:2360)
- 239434 Red Hat Update for postgresql (RHSA-2021:2397)
- 239435 Red Hat Update for rh-postgresql13-postgresql (RHSA-2021:2396)
- 239436 Red Hat Update for rh-postgresql10-postgresql (RHSA-2021:2395)
- 239437 Red Hat Update for rh-postgresql12-postgresql (RHSA-2021:2394)
- 239438 Red Hat Update for postgresql:9.6 (RHSA-2021:2393)
- 239439 Red Hat Update for postgresql:10 (RHSA-2021:2392)
- 239440 Red Hat Update for postgresql:9.6 (RHSA-2021:2391)
- 239441 Red Hat Update for postgresql:10 (RHSA-2021:2390)
- 239442 Red Hat Update for postgresql:12 (RHSA-2021:2389)
- 352471 Amazon Linux Security Advisory for postgresql96: ALAS-2021-1520
- 356175 Amazon Linux Security Advisory for postgresql : ALASPOSTGRESQL12-2023-004
- 356201 Amazon Linux Security Advisory for postgresql : ALASPOSTGRESQL11-2023-003
- 356295 Amazon Linux Security Advisory for postgresql : ALASPOSTGRESQL13-2023-003
- 376880 Alibaba Cloud Linux Security Update for postgresql (ALINUX2-SA-2021:0041)
- 377098 Alibaba Cloud Linux Security Update for postgresql:13 (ALINUX3-SA-2021:0043)
- 500542 Alpine Linux Security Update for postgresql
- 501470 Alpine Linux Security Update for postgresql
- 501993 Alpine Linux Security Update for postgresql13
- 502010 Alpine Linux Security Update for postgresql14
- 502776 Alpine Linux Security Update for postgresql15
- 504309 Alpine Linux Security Update for postgresql14
- 505668 Alpine Linux Security Update for postgresql15
- 670554 EulerOS Security Update for postgresql (EulerOS-SA-2021-2312)
- 670586 EulerOS Security Update for postgresql (EulerOS-SA-2021-2344)
- 670667 EulerOS Security Update for postgresql (EulerOS-SA-2021-2426)
- 670970 EulerOS Security Update for postgresql (EulerOS-SA-2021-2607)
- 710683 Gentoo Linux PostgreSQL Multiple Vulnerabilities (GLSA 202211-04)
- 730155 McAfee Web Gateway Multiple Vulnerabilities(WP-3580, WP-3656, WP-3815, WP-3878, WP-3882, WP-3934,WP-3935, WP-3936, WP-3999)
- 750047 SUSE Enterprise Linux Security Update for postgresql10 (SUSE-SU-2021:1782-1)
- 750050 SUSE Enterprise Linux Security Update for postgresql13 (SUSE-SU-2021:1784-1)
- 750052 SUSE Enterprise Linux Security Update for postgresql13 (SUSE-SU-2021:1785-1)
- 750053 SUSE Enterprise Linux Security Update for postgresql12 (SUSE-SU-2021:1783-1)
- 750068 SUSE Enterprise Linux Security Update for postgresql13 (SUSE-SU-2021:1785-1)
- 750162 SUSE Enterprise Linux Security Update for postgresql10 (SUSE-SU-2021:1970-1)
- 750638 OpenSUSE Security Update for postgresql10 (openSUSE-SU-2021:0894-1)
- 750657 SUSE Enterprise Linux Security Update for postgresql12 (SUSE-SU-2021:1994-1)
- 750776 OpenSUSE Security Update for postgresql13 (openSUSE-SU-2021:1785-1)
- 750808 OpenSUSE Security Update for postgresql10 (openSUSE-SU-2021:1970-1)
- 750816 OpenSUSE Security Update for postgresql12 (openSUSE-SU-2021:1994-1)
- 750982 SUSE Enterprise Linux Security Update for postgresql10 (SUSE-SU-2021:2777-1)
- 751264 SUSE Enterprise Linux Security Update for postgresql10 (SUSE-SU-2021:3481-1)
- 752529 SUSE Enterprise Linux Security Update for postgresql12 (SUSE-SU-2022:2958-1)
- 900045 CBL-Mariner Linux Security Update for postgresql 12.6
- 902889 Common Base Linux Mariner (CBL-Mariner) Security Update for postgresql (4338)
- 940196 AlmaLinux Security Update for postgresql:9.6 (ALSA-2021:2360)
- 940218 AlmaLinux Security Update for postgresql:13 (ALSA-2021:2375)
- 940343 AlmaLinux Security Update for postgresql:10 (ALSA-2021:2361)
- 940413 AlmaLinux Security Update for postgresql:12 (ALSA-2021:2372)
- 960053 Rocky Linux Security Update for postgresql:9.6 (RLSA-2021:2360)
- 960091 Rocky Linux Security Update for postgresql:13 (RLSA-2021:2375)
- 960093 Rocky Linux Security Update for postgresql:12 (RLSA-2021:2372)
- 960101 Rocky Linux Security Update for postgresql:10 (RLSA-2021:2361)