CVE-2010-0442
MEDIUM severity · CVSS 6.5 · CWE-189
6.5CVSS MEDIUM
Summary
The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument, as demonstrated by a SELECT statement that contains a call to the substring function for a bit string, related to an "overflow."
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)13%
AV:N/AC:L/Au:S/C:P/I:P/A:P
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://archives.postgresql.org/pgsql-committers/2010-01/msg00125.phpAdvisory
- http://archives.postgresql.org/pgsql-hackers/2010-01/msg00634.phpAdvisory
- http://git.postgresql.org/gitweb?p=postgresql.git%3Ba=commit%3Bh=75dea10196c31d98d98c0bafeeb576ae99c09b12Advisory
- http://git.postgresql.org/gitweb?p=postgresql.git%3Ba=commit%3Bh=b15087cb39ca9e4bde3c8920fcee3741045d2b83Advisory
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=567058Advisory
- http://intevydis.blogspot.com/2010/01/postgresql-8023-bitsubstr-overflow.htmlAdvisory
- http://secunia.com/advisories/39566
- http://secunia.com/advisories/39820