Information disclosure in PostgreSQL - CVE-2019-10209
Published: August 8, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to way PostgreSQL processes user-defined hash equality operators. A remote attacker can under certain circumstances read arbitrary bytes from server memory.
Note, exploitation of this vulnerability requires a superuser to create unusual operators.
Affected software
Arch Linux
Opensuse
Fedora
postgresql-9.5 (Ubuntu package)
postgresql-10 (Ubuntu package)
postgresql-11 (Debian package)
postgresql (Alpine package)
postgresql-11 (Ubuntu package)
postgresql
libpq
How to mitigate CVE-2019-10209
postgresql-9.5 (Ubuntu package) - update to 9.5.19-0ubuntu0.16.04.1
postgresql-10 (Ubuntu package) - update to 10.10-0ubuntu0.18.04.1
postgresql-11 (Debian package) - update to 11.5-1+deb10u1
postgresql (Alpine package) - update to 11.5-r0
postgresql-11 (Ubuntu package) - update to 11.5-0ubuntu0.19.04.1
postgresql - addressed in versions 10.10-1.fc29, 11.5-1.fc30
libpq - update to 11.5-1.fc30
External References
Related Security Bulletins
- Multiple vulnerabilities in PostgreSQL
- Ubuntu update for PostgreSQL
- Debian update for postgresql-11
- Arch Linux update for postgresql-libs
- Arch Linux update for postgresql
- OpenSUSE Linux update for SUSE Manager Client Tools
- Information disclosure in postgresql (Alpine package)
- Fedora 30 update for libpq, postgresql
- Fedora 29 update for postgresql