PostgreSQL Numeric Errors Vulnerability - CVE-2010-0442 - Vulnerability Database

PostgreSQL Numeric Errors Vulnerability - CVE-2010-0442

Medium
Reference: CVE-2010-0442
Title: PostgreSQL Numeric Errors Vulnerability
Overview:

The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23 8.1.11 and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument as demonstrated by a SELECT statement that contains a call to the substring function for a bit string related to an quotoverflow.quot