#VU18862 Buffer overflow in PostgreSQL - CVE-2019-10164
Published: June 20, 2019
PostgreSQL
PostgreSQL Global Development Group
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing a specifically crafted message during the SCRAM authentication process in a libpq-enabled client. A remote attacker can trick the victim to connect to a malicious PostgreSQL server, trigger memory corruption and execute arbitrary code on the target client system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.