IT

Tracker / CVE-2019-10210

CVE-2019-10210

High 7.0

Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporary file.

Affected products and versions

postgresql postgresql · … → 9.4.24
postgresql postgresql · 10.0 → 10.10
postgresql postgresql · 11.0 → 11.5
postgresql postgresql · 9.5.0 → 9.5.19
postgresql postgresql · 9.6.0 → 9.6.15

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References