6.5

CVE-2010-0442

Exploit

The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument, as demonstrated by a SELECT statement that contains a call to the substring function for a bit string, related to an "overflow."

Data is provided by the National Vulnerability Database (NVD)
PostgresqlPostgresql Version >= 7.4 < 7.4.28
PostgresqlPostgresql Version >= 8.0 < 8.0.24
PostgresqlPostgresql Version >= 8.1 < 8.1.20
PostgresqlPostgresql Version >= 8.2 < 8.2.16
PostgresqlPostgresql Version >= 8.3 < 8.3.10
PostgresqlPostgresql Version >= 8.4 < 8.4.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 16.19% 0.945
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
http://securitytracker.com/id?1023510
Third Party Advisory
VDB Entry
http://ubuntu.com/usn/usn-933-1
Third Party Advisory
http://www.securityfocus.com/bid/37973
Third Party Advisory
Exploit
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=559194
Third Party Advisory
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=559259
Third Party Advisory
Issue Tracking