
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-21469 is a disputed vulnerability discovered in PostgreSQL 12.2 that was reported on August 22, 2023. The vulnerability allegedly allows attackers to cause a denial of service by repeatedly sending SIGHUP signals to the PostgreSQL server process (NVD).
The vulnerability has been assigned a CVSS v3.1 base score of 4.4 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H. The issue involves a potential stack overflow condition that occurs when SIGHUP signals are continuously sent to the PostgreSQL server process, which can lead to process termination (PostgreSQL Mailing List).
The potential impact is limited to denial of service through server process termination. However, the vendor disputes the security implications as the SIGHUP signals can only be sent by users with elevated privileges: PostgreSQL superusers, users with pgreloadconf access, or users with sufficient OS-level privileges (postgres or root account) (NVD).
The issue was addressed in subsequent PostgreSQL releases. The fix was implemented in the main development branch but was initially not backported due to the limited security impact and the need for further testing (PostgreSQL Mailing List).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."