The vendor explicitly identifies these products as affected by this CVE.
- postgresql as a component of Red Hat Enterprise Linux 6
- postgresql-contrib as a component of Red Hat Enterprise Linux 6
- postgresql-devel as a component of Red Hat Enterprise Linux 6
- postgresql-docs as a component of Red Hat Enterprise Linux 6
- postgresql-libs as a component of Red Hat Enterprise Linux 6
- postgresql-plperl as a component of Red Hat Enterprise Linux 6
- postgresql-plpython as a component of Red Hat Enterprise Linux 6
- postgresql-pltcl as a component of Red Hat Enterprise Linux 6
- postgresql-server as a component of Red Hat Enterprise Linux 6
- postgresql-test as a component of Red Hat Enterprise Linux 6
- postgresql.src as a component of Red Hat Enterprise Linux 6
- postgresql as a component of Red Hat Enterprise Linux 7
- Summary
- A flaw was found in PostgreSQL. This vulnerability, an externally-controlled format string in the `timeofday()` function, allows a remote attacker to craft specific timezone zones. Successful exploitation can lead to the retrieval of sensitive portions of server memory, potentially disclosing confidential information.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
