Candidate: CVE-2010-0733 PublicDate: 2010-03-19 19:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0733 http://archives.postgresql.org/pgsql-bugs/2009-10/msg00277.php Description: Integer overflow in src/backend/executor/nodeHash.c in PostgreSQL 8.4.1 and earlier, and 8.5 through 8.5alpha2, allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with many LEFT JOIN clauses, related to certain hashtable size calculations. Ubuntu-Description: Notes: Bugs: https://bugzilla.redhat.com/show_bug.cgi?id=546621 http://archives.postgresql.org/pgsql-bugs/2009-10/msg00277.php Priority: medium Discovered-by: Assigned-to: CVSS: Patches_postgresql-7.4: upstream_postgresql-7.4: needs-triage dapper_postgresql-7.4: ignored (reached end-of-life) hardy_postgresql-7.4: DNE intrepid_postgresql-7.4: DNE jaunty_postgresql-7.4: DNE karmic_postgresql-7.4: DNE lucid_postgresql-7.4: DNE maverick_postgresql-7.4: DNE natty_postgresql-7.4: DNE oneiric_postgresql-7.4: DNE devel_postgresql-7.4: DNE Patches_postgresql-8.0: upstream_postgresql-8.0: needs-triage dapper_postgresql-8.0: ignored (reached end-of-life) hardy_postgresql-8.0: DNE intrepid_postgresql-8.0: DNE jaunty_postgresql-8.0: DNE karmic_postgresql-8.0: DNE lucid_postgresql-8.0: DNE maverick_postgresql-8.0: DNE natty_postgresql-8.0: DNE oneiric_postgresql-8.0: DNE devel_postgresql-8.0: DNE Patches_postgresql-8.1: upstream_postgresql-8.1: released (8.1.19) dapper_postgresql-8.1: released (8.1.19-0ubuntu0.6.06) hardy_postgresql-8.1: DNE intrepid_postgresql-8.1: DNE jaunty_postgresql-8.1: DNE karmic_postgresql-8.1: DNE lucid_postgresql-8.1: DNE maverick_postgresql-8.1: DNE natty_postgresql-8.1: DNE oneiric_postgresql-8.1: DNE devel_postgresql-8.1: DNE Patches_postgresql-8.2: upstream_postgresql-8.2: released (8.2.15) dapper_postgresql-8.2: DNE hardy_postgresql-8.2: ignored (reached end-of-life) intrepid_postgresql-8.2: DNE jaunty_postgresql-8.2: DNE karmic_postgresql-8.2: DNE lucid_postgresql-8.2: DNE maverick_postgresql-8.2: DNE natty_postgresql-8.2: DNE oneiric_postgresql-8.2: DNE devel_postgresql-8.2: DNE Patches_postgresql-8.3: upstream_postgresql-8.3: released (8.3.9) dapper_postgresql-8.3: DNE hardy_postgresql-8.3: released (8.3.9-0ubuntu8.04) intrepid_postgresql-8.3: released (8.3.9-0ubuntu8.10) jaunty_postgresql-8.3: released (8.3.9-0ubuntu9.04) karmic_postgresql-8.3: ignored (reached end-of-life) lucid_postgresql-8.3: DNE maverick_postgresql-8.3: DNE natty_postgresql-8.3: DNE oneiric_postgresql-8.3: DNE devel_postgresql-8.3: DNE Patches_postgresql-8.4: upstream: http://git.postgresql.org/gitweb?p=postgresql.git;a=commitdiff;h=64b057e6823655fb6c5d1f24a28f236b94dd6c54 upstream_postgresql-8.4: released (8.4.2) dapper_postgresql-8.4: DNE hardy_postgresql-8.4: DNE intrepid_postgresql-8.4: DNE jaunty_postgresql-8.4: DNE karmic_postgresql-8.4: released (8.4.2-0ubuntu9.10) lucid_postgresql-8.4: released (8.4.3-1) maverick_postgresql-8.4: released (8.4.3-1) natty_postgresql-8.4: released (8.4.3-1) oneiric_postgresql-8.4: released (8.4.3-1) devel_postgresql-8.4: released (8.4.3-1)