↑↓ select↵ open⌫ change scopeOpen full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

CVE-2019-10210

The EnterpriseDB Windows installer writes a password to a temporary file in its installation directory, creates initial databases, and deletes the file. During those seconds while the file exists, a local attacker can read the PostgreSQL superuser password from the file. The PostgreSQL project thanks Noah Misch for reporting this problem.

Version Information

Affected branchIntroducedFixed InFix Published
10—10.102019-08-08
11—11.52019-08-08
9.4—9.4.242019-08-08
9.5—9.5.192019-08-08
9.6—9.6.152019-08-08

CVSS 3.0

Overall Score6.7
Componentpackaging
VectorAV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

First published: 2019-08-08

Original security advisory · JSON · All advisories