vulnerability

PostgreSQL: CVE-2019-3466: pg_ctlcluster script in postgresql-common does not drop privileges when creating socket/statistics temporary directories

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
2019-11-20
Added
2019-12-05
Modified
2024-01-15

Description

The pg_ctlcluster script in postgresql-common in versions prior to 210 didn't drop privileges when creating socket/statistics temporary directories, which could result in local privilege escalation.

Solution

postgres-upgrade-12_1
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.