peter bassill · operator
$ cve CVE-2010-0442 JSON

CVE-2010-0442 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 13.3% (pctl 96)

Patch early

A public exploit exists.

Description

The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument, as demonstrated by a SELECT statement that contains a call to the substring function for a bit string, related to an "overflow."

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS13.26% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-189
On CISA KEVno
Public exploityes
Published2010-02-02
Last modified2026-06-16

Affected (1)

VendorProduct
postgresqlpostgresql

Public exploits

SourceTitleDate
exploit-dbPostgreSQL - 'bitsubstr' Buffer Overflow2010-01-27

References

→ the Explorer  ·  watch your stack  ·  NVD