CVE-2010-0442

Priority
Medium
Description
The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23,
8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of
service (daemon crash) or have unspecified other impact via vectors
involving a negative integer in the third argument, as demonstrated by a
SELECT statement that contains a call to the substring function for a bit
string, related to an "overflow."
References
Bugs
Notes
mdeslaur> this was fixed in the -updates pocket, but not the -security
mdeslaur> pocket.
Package
Upstream:released (8.4.3)
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):released (8.4.3-1)
Ubuntu 11.04 (Natty Narwhal):released (8.4.3-1)
Ubuntu 11.10 (Oneiric Ocelot):released (8.4.3-1)
Ubuntu 12.04 LTS (Precise Pangolin):released (8.4.3-1)
Patches:
Upstream:http://git.postgresql.org/gitweb?p=postgresql.git;a=commitdiff;h=75dea10196c31d98d98c0bafeeb576ae99c09b12
Upstream:http://git.postgresql.org/gitweb?p=postgresql.git;a=commitdiff;h=b15087cb39ca9e4bde3c8920fcee3741045d2b83
Package
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 11.04 (Natty Narwhal):DNE
Ubuntu 11.10 (Oneiric Ocelot):DNE
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Package
Upstream:released (8.1.20)
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 11.04 (Natty Narwhal):DNE
Ubuntu 11.10 (Oneiric Ocelot):DNE
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Package
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 11.04 (Natty Narwhal):DNE
Ubuntu 11.10 (Oneiric Ocelot):DNE
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Package
Upstream:released (8.3.10)
Ubuntu 8.04 LTS (Hardy Heron):released (8.3.10-0ubuntu8.04)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 11.04 (Natty Narwhal):DNE
Ubuntu 11.10 (Oneiric Ocelot):DNE
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Package
Upstream:released (8.2.16)
Ubuntu 8.04 LTS (Hardy Heron):ignored (reached end-of-life)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 11.04 (Natty Narwhal):DNE
Ubuntu 11.10 (Oneiric Ocelot):DNE
Ubuntu 12.04 LTS (Precise Pangolin):DNE
More Information

Valid XHTML 1.0 Strict

Updated: 2012-06-01 15:20:42 UTC (commit 5347)