CVE-2010-4015: Buffer Overflow
Buffer overflow in the gettoken function in contrib/intarray/intbool.c in the intarray array module in PostgreSQL 9.0.x before 9.0.3, 8.4.x before 8.4.7, 8.3.x before 8.3.14, and 8.2.x before 8.2.20 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via integers with a large number of digits to unspecified functions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4015?
CVE-2010-4015 is rated as a high severity vulnerability that can lead to denial of service and potential remote code execution.
How do I fix CVE-2010-4015?
To fix CVE-2010-4015, you should upgrade PostgreSQL to version 9.0.3 or later, 8.4.7 or later, 8.3.14 or later, or 8.2.20 or later.
Which versions are affected by CVE-2010-4015?
CVE-2010-4015 affects PostgreSQL versions 9.0.x before 9.0.3, 8.4.x before 8.4.7, 8.3.x before 8.3.14, and 8.2.x before 8.2.20.
Who can exploit CVE-2010-4015?
CVE-2010-4015 can be exploited by remote authenticated users to cause a denial of service.
What is the impact of CVE-2010-4015?
The impact of CVE-2010-4015 includes crashing the database and potentially executing arbitrary code.