First published: Tue Oct 29 2019(Updated: )
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporary file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
PostgreSQL | <9.4.24 | |
PostgreSQL | >=9.5.0<9.5.19 | |
PostgreSQL | >=9.6.0<9.6.15 | |
PostgreSQL | >=10.0<10.10 | |
PostgreSQL | >=11.0<11.5 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-10210.
The severity level of CVE-2019-10210 is high, with a severity value of 7.
The affected software versions are from 9.4.24 to 11.5, 10.10, 9.6.15, 9.5.19, and 9.4.24.
The vulnerability allows a superuser to write a password to an unprotected temporary file.
No, Microsoft Windows is not affected by the PostgreSQL Windows installer vulnerability.