CVE-2010-0442
Published: 2 February 2010
The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument, as demonstrated by a SELECT statement that contains a call to the substring function for a bit string, related to an "overflow."
Notes
Author | Note |
---|---|
mdeslaur |
this was fixed in the -updates pocket, but not the -security pocket. |
Priority
Status
Package | Release | Status |
---|---|---|
postgresql-7.4
Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
hardy |
Does not exist
|
|
intrepid |
Does not exist
|
|
jaunty |
Does not exist
|
|
karmic |
Does not exist
|
|
lucid |
Does not exist
|
|
maverick |
Does not exist
|
|
natty |
Does not exist
|
|
oneiric |
Does not exist
|
|
upstream |
Needs triage
|
|
postgresql-8.0
Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
hardy |
Does not exist
|
|
intrepid |
Does not exist
|
|
jaunty |
Does not exist
|
|
karmic |
Does not exist
|
|
lucid |
Does not exist
|
|
maverick |
Does not exist
|
|
natty |
Does not exist
|
|
oneiric |
Does not exist
|
|
upstream |
Needs triage
|
|
postgresql-8.1
Launchpad, Ubuntu, Debian |
dapper |
Released
(8.1.20-0ubuntu0.6.06)
|
hardy |
Does not exist
|
|
intrepid |
Does not exist
|
|
jaunty |
Does not exist
|
|
karmic |
Does not exist
|
|
lucid |
Does not exist
|
|
maverick |
Does not exist
|
|
natty |
Does not exist
|
|
oneiric |
Does not exist
|
|
upstream |
Released
(8.1.20)
|
|
postgresql-8.2
Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Ignored
(end of life)
|
|
intrepid |
Does not exist
|
|
jaunty |
Does not exist
|
|
karmic |
Does not exist
|
|
lucid |
Does not exist
|
|
maverick |
Does not exist
|
|
natty |
Does not exist
|
|
oneiric |
Does not exist
|
|
upstream |
Released
(8.2.16)
|
|
postgresql-8.3
Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Released
(8.3.10-0ubuntu8.04)
|
|
intrepid |
Ignored
(end of life)
|
|
jaunty |
Released
(8.3.10-0ubuntu9.04)
|
|
karmic |
Ignored
(end of life)
|
|
lucid |
Does not exist
|
|
maverick |
Does not exist
|
|
natty |
Does not exist
|
|
oneiric |
Does not exist
|
|
upstream |
Released
(8.3.10)
|
|
postgresql-8.4
Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Does not exist
|
|
intrepid |
Does not exist
|
|
jaunty |
Does not exist
|
|
karmic |
Released
(8.4.3-0ubuntu9.10)
|
|
lucid |
Released
(8.4.3-1)
|
|
maverick |
Released
(8.4.3-1)
|
|
natty |
Released
(8.4.3-1)
|
|
oneiric |
Released
(8.4.3-1)
|
|
upstream |
Released
(8.4.3)
|
|
Patches:
upstream: http://git.postgresql.org/gitweb?p=postgresql.git;a=commitdiff;h=75dea10196c31d98d98c0bafeeb576ae99c09b12 upstream: http://git.postgresql.org/gitweb?p=postgresql.git;a=commitdiff;h=b15087cb39ca9e4bde3c8920fcee3741045d2b83 |