CVE-2020-21469
MEDIUMPostgresql - Buffer Overflow
Title source: ruleDescription
An issue was discovered in PostgreSQL 12.2 allows attackers to cause a denial of service via repeatedly sending SIGHUP signals. NOTE: this is disputed by the vendor because untrusted users cannot send SIGHUP signals; they can only be sent by a PostgreSQL superuser, a user with pg_reload_conf access, or a user with sufficient privileges at the OS level (the postgres account or the root account).
References (3)
Scores
CVSS v3
4.4
EPSS
0.0003
EPSS Percentile
6.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-120
Status
published
Affected Products (1)
postgresql/postgresql
Timeline
Published
Aug 22, 2023
Tracked Since
Feb 18, 2026