CVE-2019-10164

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-10164
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-10164.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-10164
Downstream
Related
Published
2019-06-26T16:15:09Z
Modified
2025-10-06T11:50:43.203690Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpose-crafted value. This often suffices to execute arbitrary code as the PostgreSQL operating system account.

References

Affected packages

Git / git.postgresql.org/git/postgresql.git

Affected ranges

Type
GIT
Repo
https://git.postgresql.org/git/postgresql.git
Events
Introduced
5df0e99bea1c3e5fbffa7fbd0982da88ea149bb6
Fixed
cb4cb7401e12f5796a5e16fabddeffae3cac39b5

Affected versions

Other

REL_10_0
REL_10_1
REL_10_2
REL_10_3
REL_10_4
REL_10_5
REL_10_6
REL_10_7
REL_10_8