CVE-2019-3466
Description
The pg_ctlcluster script in postgresql-common in versions prior to 210 didn't drop privileges when creating socket/statistics temporary directories, which could result in local privilege escalation.
CWE
- (none)
Affected
- n/a / postgresql-common (Debian-specific Postgres management tools) — v=Versions before 210 [affected]
CVSS
- (none)
References
- https://blog.mirch.io/2019/11/15/cve-2019-3466-debian-ubuntu-pg_ctlcluster-privilege-escalation/ x_refsource_MISC
- https://usn.ubuntu.com/4194-2/ vendor-advisory, x_refsource_UBUNTU
Source
cvelistV5-main/cves/2019/3xxx/CVE-2019-3466.json