CVE-2019-10164

HIGH

Description

PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpose-crafted value. This often suffices to execute arbitrary code as the PostgreSQL operating system account.

References

http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00035.html

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10164

https://lists.fedoraproject.org/archives/list/[email protected]/message/MAGE6H4FWLKFLHLWVYNPYGQRPIXTUWGB/

https://lists.fedoraproject.org/archives/list/[email protected]/message/TTKEHXGDXYYD6WYDIIQJP4GDQJSENDJK/

https://www.postgresql.org/about/news/1949/

Details

Source: MITRE

Published: 2019-06-26

Updated: 2019-07-21

Type: CWE-119

Risk Information

CVSS v2.0

Base Score: 9

Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 8

Severity: HIGH

CVSS v3.0

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 2.8

Severity: HIGH