[3.7] postgresql: Stack-based buffer overflow via setting a password (CVE-2019-10164)ID: oval:org.secpod.oval:def:1801495 | Date: (C)2019-07-09 (M)2023-11-10 |
Class: PATCH | Family: unix |
PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user"s own password to a purpose-crafted value. This often suffices to execute arbitrary code as the PostgreSQL operating system account.
Platform: |
Alpine Linux 3.7 |