Back to search
CVE-2010-4015
Published: Feb 2, 2011
Modified: Aug 7, 2024
PUBLISHED
Description
Buffer overflow in the gettoken function in contrib/intarray/_int_bool.c in the intarray array module in PostgreSQL 9.0.x before 9.0.3, 8.4.x before 8.4.7, 8.3.x before 8.3.14, and 8.2.x before 8.2.20 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via integers with a large number of digits to unspecified functions.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
ADV-2011-0283
vdb-entry
x_refsource_VUPEN
70740
vdb-entry
x_refsource_OSVDB
43144
third-party-advisory
x_refsource_SECUNIA
HPSBMU02781
vendor-advisory
x_refsource_HP
RHSA-2011:0198
vendor-advisory
x_refsource_REDHAT
FEDORA-2011-0990
vendor-advisory
x_refsource_FEDORA
RHSA-2011:0197
vendor-advisory
x_refsource_REDHAT
http://www.postgresql.org/about/news.1289
x_refsource_CONFIRM
ADV-2011-0349
vdb-entry
x_refsource_VUPEN
43187
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2011:005
vendor-advisory
x_refsource_SUSE
USN-1058-1
vendor-advisory
x_refsource_UBUNTU
MDVSA-2011:021
vendor-advisory
x_refsource_MANDRIVA
ADV-2011-0262
vdb-entry
x_refsource_VUPEN
ADV-2011-0303
vdb-entry
x_refsource_VUPEN
DSA-2157
vendor-advisory
x_refsource_DEBIAN
ADV-2011-0287
vdb-entry
x_refsource_VUPEN
43155
third-party-advisory
x_refsource_SECUNIA
43154
third-party-advisory
x_refsource_SECUNIA
43188
third-party-advisory
x_refsource_SECUNIA
http://www.postgresql.org/support/security
x_refsource_CONFIRM
46084
vdb-entry
x_refsource_BID
postgresql-gettoken-buffer-overflow(65060)
vdb-entry
x_refsource_XF
43240
third-party-advisory
x_refsource_SECUNIA
FEDORA-2011-0963
vendor-advisory
x_refsource_FEDORA
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
x_refsource_CONFIRM
ADV-2011-0278
vdb-entry
x_refsource_VUPEN
ADV-2011-0299
vdb-entry
x_refsource_VUPEN
SSRT100617
vendor-advisory
x_refsource_HP
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now