CVE-2019-10164 PUBLISHED

PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpose-crafted value. This often suffices to execute arbitrary code as the PostgreSQL operating system account.

EPSS 5.90% · 90.5th percentile

Risk Scores

EPSS Score
5.90%
90.5th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSpostgresql-100, 10.1-1, 10.1-2

Timeline

References

Open in Interactive Console →