CVE-2019-10164

PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpose-crafted value. This often suffices to execute arbitrary code as the PostgreSQL operating system account.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
redhatCNA
7.5 HIGH
NETWORK
HIGH
LOW
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
postgresqlpostgresql
10.0 ≤
𝑥
< 10.9
postgresqlpostgresql
11.0 ≤
𝑥
< 11.4
redhatenterprise_linux
8.0
opensuseleap
15.0
opensuseleap
15.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
postgresql-10
disco
dne
cosmic
Fixed 10.9-0ubuntu0.18.10.1
released
bionic
Fixed 10.9-0ubuntu0.18.04.1
released
xenial
dne
trusty
dne
postgresql-11
disco
Fixed 11.4-0ubuntu0.19.04.1
released
cosmic
dne
bionic
dne
xenial
dne
trusty
dne
postgresql-9.1
disco
dne
cosmic
dne
bionic
dne
xenial
dne
trusty
dne
postgresql-9.3
disco
dne
cosmic
dne
bionic
dne
xenial
dne
trusty
not-affected
postgresql-9.5
disco
dne
cosmic
dne
bionic
dne
xenial
not-affected
trusty
dne