Red Hat Bugzilla – Bug 1539613
CVE-2018-1052 postgresql: Memory disclosure in table partitioning
Last modified: 2018-03-13 01:11:42 EDT
Using a purpose-crafted insert to a partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any user can create a partitioned table suitable for this attack. Vulnerable Versions: 10
Acknowledgments: Name: the PostgreSQL project Upstream: Álvaro Herrera, David Rowley
External References: https://www.postgresql.org/about/news/1829/
Statement: This issue did not affect the versions of PostgreSQL as shipped with Red Hat Satellite 5 and CloudForms 5 as they use PostgreSQL version 9.x and this vulnerability is specific to PostgreSQL 10.x.