Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Mageia: 2019-0204 Moderate: PostgreSQL11 Stack-Based Overflow Advisory

mageia
Calendar Grey July 10, 2019
Dist Mageia Esm H88
Mageia's postgresql12 revision tackles urgent security risks associated with memory corruption issues. Discover further details.
An authenticated user could create a stack-based buffer overflow by changing their own password to a purpose-crafted value

Summary

An authenticated user could create a stack-based buffer overflow by changing their own password to a purpose-crafted value. In addition to the ability to crash the PostgreSQL server, this could be further exploited to execute arbitrary code as the PostgreSQL operating system account.
Additionally, a rogue server could send a specifically crafted message during the SCRAM authentication process and cause a libpq-enabled client to either crash or execute arbitrary code as the client's operating system account. (CVE-2019-10164)
More than 25 other bugs have been fixed too, see referenced release notes.

References

- https://bugs.mageia.org/show_bug.cgi?id=24996

- https://www.postgresql.org/about/news/postgresql-114-109-9614-9518-9423-and-12-beta-2-released-1949/

- https://www.cve.org/CVERecord?id=CVE-2019-10164

Resolution

SRPMS

- 7/core/postgresql11-11.4-1.mga7

Publication date: 10 Jul 2019
URL: https://advisories.mageia.org/MGASA-2019-0204.html
Type: security
CVE: CVE-2019-10164

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here