First published: Tue Oct 29 2019(Updated: )
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
PostgreSQL PostgreSQL | <9.4.24 | |
PostgreSQL PostgreSQL | >=9.5.0<9.5.19 | |
PostgreSQL PostgreSQL | >=9.6.0<9.6.15 | |
PostgreSQL PostgreSQL | >=10.0<10.10 | |
PostgreSQL PostgreSQL | >=11.0<11.5 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10211 is a vulnerability in the PostgreSQL Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24.
CVE-2019-10211 has a severity rating of 9.8, which is classified as critical.
The PostgreSQL Windows installer versions 11.5, 10.10, 9.6.15, 9.5.19, and 9.4.24 are affected.
CVE-2019-10211 is a vulnerability in the bundled OpenSSL of the PostgreSQL Windows installer, allowing the execution of code from an unprotected directory.
To fix CVE-2019-10211, users should update their PostgreSQL Windows installer to versions 11.5, 10.10, 9.6.15, 9.5.19, or 9.4.24.