{"id":"CVE-2019-10209","year":2019,"sequence":10209,"component":"core server","score":3.1,"cvss_version":"3.0","vector":"AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","first_published":"2019-08-08","source_url":"https://www.postgresql.org/support/security/CVE-2019-10209/","facts":{"affected":{"11":"11"},"component":"core server","cvss_version":"3.0","description_en":"In a database containing hypothetical, user-defined hash equality operators, an attacker could read arbitrary bytes of server memory. For an attack to become possible, a superuser would need to create unusual operators. It is possible for operators not purpose-crafted for attack to have the properties that enable an attack, but we are not aware of specific examples.\n\nThe PostgreSQL project thanks Andreas Seltenreich for reporting this problem.","first_published":"2019-08-08","fixed":{"11":"11.5"},"id":"CVE-2019-10209","introduced":{},"published":{"11":"2019-08-08"},"score":3.1,"title":"Memory disclosure in cross-type comparison for hashed subplan","url":"https://www.postgresql.org/support/security/CVE-2019-10209/","vector":"AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":null,"locales":["en"],"fixes":[{"major":"11","fixed_version":"11.5","introduced":null,"published_date":"2019-08-08","facts":{"fixed":"11.5","introduced":null,"published":"2019-08-08"}}],"legacy":[]}
