High severity7.8NVD Advisory· Published Nov 20, 2019· Updated Jun 17, 2026
CVE-2019-3466
CVE-2019-3466
Description
The pg_ctlcluster script in postgresql-common in versions prior to 210 didn't drop privileges when creating socket/statistics temporary directories, which could result in local privilege escalation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- PostgreSQL/postgresql-commondescription
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
- Range: <210
Patches
Vulnerability mechanics
References
2- blog.mirch.io/2019/11/15/cve-2019-3466-debian-ubuntu-pg_ctlcluster-privilege-escalation/nvdExploitPatchThird Party Advisory
- usn.ubuntu.com/4194-2/nvd
News mentions
0No linked articles in our index yet.