<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:30:35 +0000</lastBuildDate>
    <item>
      <title>bdu:2019-04232</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-04232</link>
      <description>bdu:2019-04232</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-04232</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2018-1053 — CVE-2018-1053 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2018-1053</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2018-1053</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-SX71048 — Security fixes in postgresql 10.2-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-sx71048</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: postgresql&lt;/p&gt;
&lt;p&gt;Package postgresql version 10.2-r0 fixes 2 vulnerabilities: CVE-2018-1052, CVE-2018-1053&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: postgresql&lt;/p&gt;
&lt;p&gt;Package postgresql version 10.2-r0 fixes 2 vulnerabilities: CVE-2018-1052, CVE-2018-1053&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-sx71048</guid>
    </item>
    <item>
      <title>cnvd-2018-05754</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-05754</link>
      <description>cnvd-2018-05754</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-05754</guid>
    </item>
    <item>
      <title>EUVD-2026-185561</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-185561</link>
      <description>EUVD-2026-185561</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-185561</guid>
    </item>
    <item>
      <title>fkie_cve-2018-1053</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-1053</link>
      <description>&lt;p&gt;In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in current working directory containing the output of `pg_dumpall -g` under umask which was in effect when the user invoked pg_upgrade, and not under 0077 which is normally used for other temporary files. This can allow an authenticated attacker to read or modify the one file, which may contain encrypted or unencrypted database passwords. The attack is infeasible if a directory mode blocks the attacker searching the current working directory or if the prevailing umask blocks the attacker opening the file.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in current working directory containing the output of `pg_dumpall -g` under umask which was in effect when the user invoked pg_upgrade, and not under 0077 which is normally used for other temporary files. This can allow an authenticated attacker to read or modify the one file, which may contain encrypted or unencrypted database passwords. The attack is infeasible if a directory mode blocks the attacker searching the current working directory or if the prevailing umask blocks the attacker opening the file.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-1053</guid>
    </item>
    <item>
      <title>GHSA-h73g-3m4r-j2cr</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h73g-3m4r-j2cr</link>
      <description>&lt;p&gt;In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in current working directory containing the output of `pg_dumpall -g` under umask which was in effect when the user invoked pg_upgrade, and not under 0077 which is normally used for other temporary files. This can allow an authenticated attacker to read or modify the one file, which may contain encrypted or unencrypted database passwords. The attack is infeasible if a directory mode blocks the attacker searching the current working directory or if the prevailing umask blocks the attacker opening the file.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in current working directory containing the output of `pg_dumpall -g` under umask which was in effect when the user invoked pg_upgrade, and not under 0077 which is normally used for other temporary files. This can allow an authenticated attacker to read or modify the one file, which may contain encrypted or unencrypted database passwords. The attack is infeasible if a directory mode blocks the attacker searching the current working directory or if the prevailing umask blocks the attacker opening the file.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h73g-3m4r-j2cr</guid>
    </item>
    <item>
      <title>gsd-2018-1053</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-1053</link>
      <description>gsd-2018-1053</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-1053</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11184-1 — postgresql10-10.18-1.3 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11184-1</link>
      <description>&lt;p&gt;postgresql10-10.18-1.3 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;postgresql10-10.18-1.3 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11184-1</guid>
    </item>
    <item>
      <title>RHSA-2018:2511 — Red Hat Security Advisory: rh-postgresql95-postgresql security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2018:2511</link>
      <description>&lt;p&gt;postgresql: Memory disclosure in JSON functions postgresql: INSERT ... ON CONFLICT DO UPDATE fails to enforce SELECT privileges postgresql: pg_upgrade creates file of sensitive metadata under prevailing umask postgresql: Uncontrolled search path element in pg_dump and other client applications postgresql: Certain host connection parameters defeat client-side security defenses postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;postgresql: Memory disclosure in JSON functions postgresql: INSERT ... ON CONFLICT DO UPDATE fails to enforce SELECT privileges postgresql: pg_upgrade creates file of sensitive metadata under prevailing umask postgresql: Uncontrolled search path element in pg_dump and other client applications postgresql: Certain host connection parameters defeat client-side security defenses postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2018:2511</guid>
    </item>
    <item>
      <title>SUSE-SU-2018:0506-1 — Security update for postgresql94</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2018:0506-1</link>
      <description>&lt;p&gt;Security update for postgresql94&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for postgresql94&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2018:0506-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-1053</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1053</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: postgresql-9.3, Ubuntu:16.04:LTS: postgresql-9.5&lt;/p&gt;
&lt;p&gt;In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in current working directory containing the output of `pg_dumpall -g` under umask which was in effect when the user invoked pg_upgrade, and not under 0077 which is normally used for other temporary files. This can allow an authenticated attacker to read or modify the one file, which may contain encrypted or unencrypted database passwords. The attack is infeasible if a directory mode blocks the attacker searching the current working directory or if the prevailing umask blocks the attacker opening the file.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: postgresql-9.3, Ubuntu:16.04:LTS: postgresql-9.5&lt;/p&gt;
&lt;p&gt;In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in current working directory containing the output of `pg_dumpall -g` under umask which was in effect when the user invoked pg_upgrade, and not under 0077 which is normally used for other temporary files. This can allow an authenticated attacker to read or modify the one file, which may contain encrypted or unencrypted database passwords. The attack is infeasible if a directory mode blocks the attacker searching the current working directory or if the prevailing umask blocks the attacker opening the file.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1053</guid>
    </item>
  </channel>
</rss>
