Description
The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows attackers to bypass intended access restrictions and consequently obtain sensitive server memory information or cause a denial of service (server crash) via a crafted bytea value in a BRIN index page.
Remediation
References
Related Vulnerabilities
Atlassian Jira Uncontrolled Search Path Element Vulnerability (CVE-2019-20400)
WordPress Plugin Slimstat Analytics PHP Object Injection (4.7)
Atlassian Jira CVE-2019-20403 Vulnerability (CVE-2019-20403)
WordPress Plugin Business Hours Indicator Cross-Site Scripting (2.3.4)
WordPress Plugin Participants Database Cross-Site Scripting (1.7.5.9)