CVE-2010-0442

Priority
Medium
Description
The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23,
8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of
service (daemon crash) or have unspecified other impact via vectors
involving a negative integer in the third argument, as demonstrated by a
SELECT statement that contains a call to the substring function for a bit
string, related to an "overflow."
References
Bugs
Notes
 mdeslaur> this was fixed in the -updates pocket, but not the -security
 mdeslaur> pocket.
Package
Upstream:released (8.4.3)
Ubuntu 12.04 LTS (Precise Pangolin):released (8.4.3-1)
Patches:
Upstream:http://git.postgresql.org/gitweb?p=postgresql.git;a=commitdiff;h=75dea10196c31d98d98c0bafeeb576ae99c09b12
Upstream:http://git.postgresql.org/gitweb?p=postgresql.git;a=commitdiff;h=b15087cb39ca9e4bde3c8920fcee3741045d2b83
Package
Upstream:needs-triage
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Package
Upstream:released (8.1.20)
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Package
Upstream:needs-triage
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Package
Upstream:released (8.3.10)
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Package
Upstream:released (8.2.16)
Ubuntu 12.04 LTS (Precise Pangolin):DNE
More Information

Valid XHTML 1.0 Strict

Updated: 2015-07-29 20:37:55 UTC (commit 9756)