CVE-2010-0442

Publication date 2 February 2010

Last updated 24 July 2024


Ubuntu priority

The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument, as demonstrated by a SELECT statement that contains a call to the substring function for a bit string, related to an "overflow."

Read the notes from the security team

Status

Package Ubuntu Release Status
postgresql-7.4 11.10 oneiric Not in release
11.04 natty Not in release
10.10 maverick Not in release
10.04 LTS lucid Not in release
9.10 karmic Not in release
9.04 jaunty Not in release
8.10 intrepid Not in release
8.04 LTS hardy Not in release
6.06 LTS dapper Ignored end of life
postgresql-8.0 11.10 oneiric Not in release
11.04 natty Not in release
10.10 maverick Not in release
10.04 LTS lucid Not in release
9.10 karmic Not in release
9.04 jaunty Not in release
8.10 intrepid Not in release
8.04 LTS hardy Not in release
6.06 LTS dapper Ignored end of life
postgresql-8.1 11.10 oneiric Not in release
11.04 natty Not in release
10.10 maverick Not in release
10.04 LTS lucid Not in release
9.10 karmic Not in release
9.04 jaunty Not in release
8.10 intrepid Not in release
8.04 LTS hardy Not in release
6.06 LTS dapper
Fixed 8.1.20-0ubuntu0.6.06
postgresql-8.2 11.10 oneiric Not in release
11.04 natty Not in release
10.10 maverick Not in release
10.04 LTS lucid Not in release
9.10 karmic Not in release
9.04 jaunty Not in release
8.10 intrepid Not in release
8.04 LTS hardy Ignored end of life
6.06 LTS dapper Not in release
postgresql-8.3 11.10 oneiric Not in release
11.04 natty Not in release
10.10 maverick Not in release
10.04 LTS lucid Not in release
9.10 karmic Ignored end of life
9.04 jaunty
Fixed 8.3.10-0ubuntu9.04
8.10 intrepid Ignored end of life
8.04 LTS hardy
Fixed 8.3.10-0ubuntu8.04
6.06 LTS dapper Not in release
postgresql-8.4 11.10 oneiric
Fixed 8.4.3-1
11.04 natty
Fixed 8.4.3-1
10.10 maverick
Fixed 8.4.3-1
10.04 LTS lucid
Fixed 8.4.3-1
9.10 karmic
Fixed 8.4.3-0ubuntu9.10
9.04 jaunty Not in release
8.10 intrepid Not in release
8.04 LTS hardy Not in release
6.06 LTS dapper Not in release

Notes


mdeslaur

this was fixed in the -updates pocket, but not the -security pocket.

References

Related Ubuntu Security Notices (USN)

    • USN-933-1
    • PostgreSQL vulnerability
    • 28 April 2010

Other references