cbcvebase.
CVE-2019-10164
published 2019-06-26

CVE-2019-10164: PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a…

PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.71%
88.6th percentile
PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpose-crafted value. This often suffices to execute arbitrary code as the PostgreSQL operating system account.

Affected

17 ranges
VendorProductVersion rangeFixed in
fedoraprojectfedora
fedoraprojectfedora
opensuseleap
opensuseleap
postgresqlpostgresql
postgresqlpostgresql
postgresqlpostgresql>= 0 < 11.4-r011.4-r0
postgresqlpostgresql>= 0 < 11.4-r011.4-r0
postgresqlpostgresql>= 0 < 11.4-r011.4-r0
postgresqlpostgresql>= 0 < 11.4-r011.4-r0
postgresqlpostgresql>= 0 < 11.4-r011.4-r0
postgresqlpostgresql>= 0 < 10.9-r010.9-r0
postgresqlpostgresql>= 0 < 10.9-r010.9-r0
postgresqlpostgresql>= 0 < 11.4-r011.4-r0
postgresqlpostgresql>= 10.0 < 10.910.9
postgresqlpostgresql>= 11.0 < 11.411.4
redhatenterprise_linux

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.