CVE-2019-10211: Code Injection
Published Oct 29, 2019
·Updated
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory.
Affected Software
6 affected components
PostgreSQL postgresql<9.4.24
PostgreSQL postgresql>=9.5.0<9.5.19
PostgreSQL postgresql>=9.6.0<9.6.15
PostgreSQL postgresql>=10.0<10.10
PostgreSQL postgresql>=11.0<11.5
Microsoft Windows
Event History
Oct 29, 2019
CVE Published
via MITRE·01:15 PM
Data Sourced
via MITRE·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2019-10211?
CVE-2019-10211 is a vulnerability in the PostgreSQL Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24.
2
How severe is CVE-2019-10211?
CVE-2019-10211 has a severity rating of 9.8, which is classified as critical.
3
Which software versions are affected by CVE-2019-10211?
The PostgreSQL Windows installer versions 11.5, 10.10, 9.6.15, 9.5.19, and 9.4.24 are affected.
4
What is the vulnerability in CVE-2019-10211?
CVE-2019-10211 is a vulnerability in the bundled OpenSSL of the PostgreSQL Windows installer, allowing the execution of code from an unprotected directory.
5
How can I fix CVE-2019-10211?
To fix CVE-2019-10211, users should update their PostgreSQL Windows installer to versions 11.5, 10.10, 9.6.15, 9.5.19, or 9.4.24.