#VU42931 Input validation error in PostgreSQL - CVE-2013-1902
Published: April 4, 2013 / Updated: August 11, 2020
PostgreSQL
PostgreSQL Global Development Group
Description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
PostgreSQL, 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 generates insecure temporary files with predictable filenames, which has unspecified impact and attack vectors related to "graphical installers for Linux and Mac OS X."