CVE-2010-0442
CVE-2010-0442
The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument, as demonstrated by a SELECT statement that contains a call to the substring function for a bit string, related to an "overflow."
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/33571unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://archives.postgresql.org/pgsql-committers/2010-01/msg00125.phphttp://archives.postgresql.org/pgsql-hackers/2010-01/msg00634.phphttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=567058http://git.postgresql.org/gitweb?p=postgresql.git%3Ba=commit%3Bh=75dea10196c31d98d98c0bafeeb576ae99c09b12http://git.postgresql.org/gitweb?p=postgresql.git%3Ba=commit%3Bh=b15087cb39ca9e4bde3c8920fcee3741045d2b83http://intevydis.blogspot.com/2010/01/postgresql-8023-bitsubstr-overflow.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=559194https://bugzilla.redhat.com/show_bug.cgi?id=559259http://secunia.com/advisories/39566http://secunia.com/advisories/39820http://secunia.com/advisories/39939http://securitytracker.com/id?1023510