CVE-2015-0242
Published: Jan 27, 2020
Modified: Aug 6, 2024
Description
Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1, when running on a Windows system, allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a floating point number with a large precision, as demonstrated by using the to_char function.
| Vendor | Product | Versions |
|---|---|---|
PostgreSQL Global Development Group | PostgreSQL | affected before 9.0.19affected 9.1.x before 9.1.15affected 9.2.x before 9.2.10affected 9.3.x before 9.3.6affected 9.4.x before 9.4.1 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now