Bugzilla – Bug 1145091
VUL-1: CVE-2019-10209: postgresql11: Memory disclosure in cross-type comparison for hashed subplan
Last modified: 2020-05-12 11:22:50 UTC
CVE-2019-10209 In a database containing hypothetical, user-defined hash equality operators, an attacker could read arbitrary bytes of server memory. For an attack to become possible, a superuser would need to create unusual operators. It is possible for operators not purpose-crafted for attack to have the properties that enable an attack, but we are not aware of specific examples. References: https://bugzilla.redhat.com/show_bug.cgi?id=1734447 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-10209 http://www.debian.org/security/2019/dsa-4493 http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-10209.html
This is an autogenerated message for OBS integration: This bug (1145091) was mentioned in https://build.opensuse.org/request/show/723108 Factory / postgresql11
Done