A user having some UPDATE privilege on a partitioned table but lacking the SELECT privilege on some column may nonetheless be able to acquire denied-column values from an error message. This is similar to CVE-2014-8161, but the conditions for exploitation are more rare. The PostgreSQL project thanks Heikki Linnakangas for reporting this problem.
Acknowledgments: Name: Heikki Linnakangas
Created mingw-postgresql tracking bugs for this issue: Affects: fedora-all [bug 1927868] Created postgresql tracking bugs for this issue: Affects: fedora-all [bug 1927867] Created postgresql:12/postgresql tracking bugs for this issue: Affects: fedora-all [bug 1927865]
Created postgresql:11/postgresql tracking bugs for this issue: Affects: fedora-all [bug 1927871]
Upstream advisory: https://www.postgresql.org/support/security/CVE-2021-3393/
Upstream commit: https://git.postgresql.org/gitweb/?p=postgresql.git;a=commitdiff;h=6214e2b2280462cbc3aa1986e350e167651b3905
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:2372 https://access.redhat.com/errata/RHSA-2021:2372
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-3393
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Extended Update Support Via RHSA-2021:2389 https://access.redhat.com/errata/RHSA-2021:2389
This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS Via RHSA-2021:2394 https://access.redhat.com/errata/RHSA-2021:2394