CVE-2013-1902

Description

PostgreSQL, 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 generates insecure temporary files with predictable filenames, which has unspecified impact and attack vectors related to graphical installers for Linux and Mac OS X.

Risk Information

Base Score
10.0
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.55

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Postgresql 9.2.3Windows
Vulnerabilities CVE-2011-2483,CVE-2013-1902,CVE-2013-1903 are affected in Postgresql 8.3.15Windows
Vulnerabilities CVE-2011-2483,CVE-2013-1902,CVE-2013-1903,CVE-2017-7486 are affected in Postgresql 8.4.8Windows
Multiple Vulnerabilities are affected in Postgresql 9.0.4Windows
Multiple vulnerabilities affected in Postgresql 9.2.3 (For Linux)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234