CVE-2019-10129
30.07.2019, 17:15
A vulnerability was found in postgresql versions 11.x prior to 11.3. Using a purpose-crafted insert to a partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any user can create a partitioned table suitable for this attack. (Exploit prerequisites are the same as for CVE-2018-1052).Enginsight
Vendor | Product | Version |
---|---|---|
postgresql | postgresql | 11.0 ≤ 𝑥 < 11.3 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
postgresql-10 |
| ||||||||||
postgresql-11 |
| ||||||||||
postgresql-9.1 |
| ||||||||||
postgresql-9.3 |
| ||||||||||
postgresql-9.5 |
|
Common Weakness Enumeration