CVE-2019-10210: High severity postgresql vulnerability
Published Oct 29, 2019
·Updated
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporary file.
Affected Software
6 affected components
PostgreSQL postgresql<9.4.24
PostgreSQL postgresql>=9.5.0<9.5.19
PostgreSQL postgresql>=9.6.0<9.6.15
PostgreSQL postgresql>=10.0<10.10
PostgreSQL postgresql>=11.0<11.5
Microsoft Windows
Event History
Oct 29, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of the PostgreSQL Windows installer vulnerability?
The vulnerability ID is CVE-2019-10210.
2
What is the severity level of CVE-2019-10210?
The severity level of CVE-2019-10210 is high, with a severity value of 7.
3
What is the affected software version range of the PostgreSQL Windows installer vulnerability?
The affected software versions are from 9.4.24 to 11.5, 10.10, 9.6.15, 9.5.19, and 9.4.24.
4
How does the vulnerability in the PostgreSQL Windows installer work?
The vulnerability allows a superuser to write a password to an unprotected temporary file.
5
Is Microsoft Windows affected by the PostgreSQL Windows installer vulnerability?
No, Microsoft Windows is not affected by the PostgreSQL Windows installer vulnerability.