PostgreSQL CVE-2019-10129 Arbitrary Memory Disclosure Vulnerability
BID:108506
Info
PostgreSQL CVE-2019-10129 Arbitrary Memory Disclosure Vulnerability
| Bugtraq ID: | 108506 |
| Class: | Design Error |
| CVE: |
CVE-2019-10129 |
| Remote: | Yes |
| Local: | No |
| Published: | May 09 2019 12:00AM |
| Updated: | May 09 2019 12:00AM |
| Credit: | Noah Misch and the PostgreSQL Project. |
| Vulnerable: |
Ubuntu Ubuntu Linux 19.04 PostgreSQL PostgreSQL 11.2 PostgreSQL PostgreSQL 11.1 PostgreSQL PostgreSQL 11 |
| Not Vulnerable: |
PostgreSQL PostgreSQL 11.3 |
Discussion
PostgreSQL CVE-2019-10129 Arbitrary Memory Disclosure Vulnerability
PostgreSQL is prone to an arbitrary memory disclosure vulnerability.
Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks.
PostgreSQL versions prior to 11.3 are vulnerable.
PostgreSQL is prone to an arbitrary memory disclosure vulnerability.
Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks.
PostgreSQL versions prior to 11.3 are vulnerable.
Exploit / POC
PostgreSQL CVE-2019-10129 Arbitrary Memory Disclosure Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
PostgreSQL CVE-2019-10129 Arbitrary Memory Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
PostgreSQL CVE-2019-10129 Arbitrary Memory Disclosure Vulnerability
References:
References:
- PostgreSQL 11.3, 10.8, 9.6.13, 9.5.17, and 9.4.22 Released! (Postgresql)
- Release Notes (PostgreSQL)
- USN-3972-1: PostgreSQL vulnerabilities (Ubuntu)