First published: Tue Oct 29 2019(Updated: )
Postgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
PostgreSQL PostgreSQL | >=11.0<11.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10209 is a vulnerability found in PostgreSQL versions 11.x before 11.5, which allows for a memory disclosure in cross-type comparison for hashed subplan.
The severity of CVE-2019-10209 is low with a severity value of 2.2.
PostgreSQL versions 11.x before 11.5 are affected by CVE-2019-10209.
To fix CVE-2019-10209, update PostgreSQL to version 11.5 or later.
You can find more information about CVE-2019-10209 on the Red Hat Bugzilla page (https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10209) and the PostgreSQL website (https://www.postgresql.org/about/news/1960/).