First published: Wed Jan 27 2010(Updated: )
The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument, as demonstrated by a SELECT statement that contains a call to the substring function for a bit string, related to an "overflow."
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/postgresql | <0:7.4.29-1.el4_8.1 | 0:7.4.29-1.el4_8.1 |
redhat/postgresql | <0:8.1.21-1.el5_5.1 | 0:8.1.21-1.el5_5.1 |
PostgreSQL PostgreSQL | >=7.4<7.4.28 | |
PostgreSQL PostgreSQL | >=8.0<8.0.24 | |
PostgreSQL PostgreSQL | >=8.1<8.1.20 | |
PostgreSQL PostgreSQL | >=8.2<8.2.16 | |
PostgreSQL PostgreSQL | >=8.3<8.3.10 | |
PostgreSQL PostgreSQL | >=8.4<8.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)