The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary code by leveraging use of HTTP to download software.
References
Link | Resource |
---|---|
https://www.postgresql.org/support/security/ | Patch Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1378043 | Issue Tracking Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2018-08-20 14:29
Updated : 2023-01-19 12:09
NVD link : CVE-2016-7048
Mitre link : CVE-2016-7048
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
postgresql
- postgresql