The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary code by leveraging use of HTTP to download software.
| Software | From | Fixed in |
|---|---|---|
| postgresql / postgresql | 9.4.0 | 9.4.10 |
| postgresql / postgresql | 9.5.0 | 9.5.5 |
| postgresql / postgresql | - | 9.1.24 |
| postgresql / postgresql | 9.2 | 9.2.19 |
| postgresql / postgresql | 9.3 | 9.3.15 |