Bug 1734453 (CVE-2019-10210)

Summary: CVE-2019-10210 postgresql: Windows installer writes superuser password to unprotected temporary file
Product: [Other] Security Response Reporter: msiddiqu
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: akoufoud, alazarot, almorale, anon.amish, anstephe, asakala, bkearney, databases-maint, dblechte, devrim, dfediuck, eedri, etirelli, hhorak, ibek, jmlich83, jorton, jstanek, krathod, kverlaen, lpetrovi, mgoldboi, michal.skrivanek, mike, mnovotny, mperina, panovotn, paradhya, pkajaba, pkubat, praiskup, puebele, rrajasek, rsynek, sbonazzo, sdaley, security-response-team, sherold, sisharma, tgl, tlestach, vbellur, yturgema
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: postgresql 11.5, postgresql 10.10, postgresql 9.6.15, postgresql 9.5.19, postgresql 9.4.24 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-08-08 19:18:19 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1734467    

Description msiddiqu 2019-07-30 14:53:54 UTC
The installer writes a password to a temporary file in its installation
directory, creates initial databases, and deletes the file.  During those
seconds while the file exists, a local attacker can read the superuser
password from the file.

Comment 3 msiddiqu 2019-08-07 11:55:52 UTC
Acknowledgments:

Name: the PostgreSQL project
Upstream: Noah Misch

Comment 6 Product Security DevOps Team 2019-08-08 19:18:19 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2019-10210

Comment 7 msiddiqu 2019-08-09 09:43:34 UTC
External References:

https://www.postgresql.org/about/news/1960/