6.5
CVE-2010-0442
- EPSS 16.19%
- Published 02.02.2010 18:30:00
- Last modified 11.04.2025 00:51:21
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument, as demonstrated by a SELECT statement that contains a call to the substring function for a bit string, related to an "overflow."
Data is provided by the National Vulnerability Database (NVD)
Postgresql ≫ Postgresql Version >= 7.4 < 7.4.28
Postgresql ≫ Postgresql Version >= 8.0 < 8.0.24
Postgresql ≫ Postgresql Version >= 8.1 < 8.1.20
Postgresql ≫ Postgresql Version >= 8.2 < 8.2.16
Postgresql ≫ Postgresql Version >= 8.3 < 8.3.10
Postgresql ≫ Postgresql Version >= 8.4 < 8.4.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 16.19% | 0.945 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|