{"id":"CVE-2019-10164","year":2019,"sequence":10164,"component":"core server","score":7.5,"cvss_version":"3.0","vector":"AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","first_published":"2019-06-20","source_url":"https://www.postgresql.org/support/security/CVE-2019-10164/","facts":{"affected":{"10":"10","11":"11"},"component":"core server","cvss_version":"3.0","description_en":"An authenticated user could create a stack-based buffer overflow by changing their own password to a purpose-crafted value. In addition to the ability to crash the PostgreSQL server, this could be further exploited to execute arbitrary code as the PostgreSQL operating system account.\n\nAdditionally, a rogue server could send a specifically crafted message during the SCRAM authentication process and cause a libpq-enabled client to either crash or execute arbitrary code as the client's operating system account.\n\nThis issue is fixed by upgrading and restarting your PostgreSQL server as well as your libpq installations.\n\nThe PostgreSQL Project thanks Alexander Lakhin for reporting this problem.","first_published":"2019-06-20","fixed":{"10":"10.9","11":"11.4"},"id":"CVE-2019-10164","introduced":{},"published":{"10":"2019-06-20","11":"2019-06-20"},"score":7.5,"title":"Stack-based buffer overflow via setting a password","url":"https://www.postgresql.org/support/security/CVE-2019-10164/","vector":"AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"en","title":"Stack-based buffer overflow via setting a password","description":"An authenticated user could create a stack-based buffer overflow by changing their own password to a purpose-crafted value. In addition to the ability to crash the PostgreSQL server, this could be further exploited to execute arbitrary code as the PostgreSQL operating system account.\n\nAdditionally, a rogue server could send a specifically crafted message during the SCRAM authentication process and cause a libpq-enabled client to either crash or execute arbitrary code as the client's operating system account.\n\nThis issue is fixed by upgrading and restarting your PostgreSQL server as well as your libpq installations.\n\nThe PostgreSQL Project thanks Alexander Lakhin for reporting this problem.","details":null,"format":"plain","provenance":{"fetched_at":"2026-09-26T10:56:06+00:00","path":"compare/security.json","root":"source-data","sha256":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_archive_sha256":"8d8ad63581e1d27b3a0f995ded3feb81c265e38b2ac652eb22f022f52c2240ec","source_revision":"004bc292ee31c11f9a41ab007e9d8116bce29a71","source_url":"https://www.postgresql.org/support/security/"},"text_hash":"3f7298badfe21cca125938f73b60c44815bbb62360d5492aa8ab83331e8c4e33"},"locales":["en"],"fixes":[{"major":"10","fixed_version":"10.9","introduced":null,"published_date":"2019-06-20","facts":{"fixed":"10.9","introduced":null,"published":"2019-06-20"}},{"major":"11","fixed_version":"11.4","introduced":null,"published_date":"2019-06-20","facts":{"fixed":"11.4","introduced":null,"published":"2019-06-20"}}],"legacy":[]}
