CVE Database
/

CVE-2015-0242

Back to search

CVE-2015-0242

Published: Jan 27, 2020

Modified: Aug 6, 2024

PUBLISHED

Description

Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1, when running on a Windows system, allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a floating point number with a large precision, as demonstrated by using the to_char function.

VendorProductVersions

PostgreSQL Global Development Group

PostgreSQL

affected
before 9.0.19
affected
9.1.x before 9.1.15
affected
9.2.x before 9.2.10
affected
9.3.x before 9.3.6
affected
9.4.x before 9.4.1

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now