Total vulnerabilities in the database
PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpose-crafted value. This often suffices to execute arbitrary code as the PostgreSQL operating system account.
Software | From | Fixed in |
---|---|---|
postgresql / postgresql | 10.0 | 10.9 |
postgresql / postgresql | 11.0 | 11.4 |
redhat / enterprise_linux | 8.0 | 8.0.x |
fedoraproject / fedora | 29 | 29.x |
fedoraproject / fedora | 30 | 30.x |
opensuse / leap | 15.0 | 15.0.x |
opensuse / leap | 15.1 | 15.1.x |