CVE-2019-10209: Infoleak
Published Oct 29, 2019
·Updated
Postgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan.
Affected Software
1 affected component
PostgreSQL postgresql>=11.0<11.5
Event History
Oct 29, 2019
CVE Published
via MITRE·01:11 PM
Data Sourced
via MITRE·01:11 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2019-10209?
CVE-2019-10209 is a vulnerability found in PostgreSQL versions 11.x before 11.5, which allows for a memory disclosure in cross-type comparison for hashed subplan.
2
What is the severity of CVE-2019-10209?
The severity of CVE-2019-10209 is low with a severity value of 2.2.
3
Which software versions are affected by CVE-2019-10209?
PostgreSQL versions 11.x before 11.5 are affected by CVE-2019-10209.
4
How can I fix CVE-2019-10209?
To fix CVE-2019-10209, update PostgreSQL to version 11.5 or later.
5
Where can I find more information about CVE-2019-10209?
You can find more information about CVE-2019-10209 on the Red Hat Bugzilla page (https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10209) and the PostgreSQL website (https://www.postgresql.org/about/news/1960/).