[Forgot Password]
Login  Register Subscribe

24128

 
 

131573

 
 

111017

 
 

909

 
 

86402

 
 

136

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML view JSON

CVE-2010-0733Date: (C)2010-03-19   (M)2018-06-11


Integer overflow in src/backend/executor/nodeHash.c in PostgreSQL 8.4.1 and earlier, and 8.5 through 8.5alpha2, allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with many LEFT JOIN clauses, related to certain hashtable size calculations.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : CVSS Score : 3.5
Exploit Score: Exploit Score: 6.8
Impact Score: Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: Access Vector: NETWORK
Attack Complexity: Access Complexity: MEDIUM
Privileges Required: Authentication: SINGLE_INSTANCE
User Interaction: Confidentiality: NONE
Scope: Integrity: NONE
Confidentiality: Availability: PARTIAL
Integrity:  
Availability:  
  
Reference:
BID-38619
SECUNIA-39820
ADV-2010-1197
RHSA-2010:0427
RHSA-2010:0428
RHSA-2010:0429
SUSE-SR:2010:014
http://www.openwall.com/lists/oss-security/2010/03/09/2
http://www.openwall.com/lists/oss-security/2010/03/16/10
http://archives.postgresql.org/pgsql-bugs/2009-10/msg00277.php
http://archives.postgresql.org/pgsql-bugs/2009-10/msg00289.php
http://archives.postgresql.org/pgsql-bugs/2009-10/msg00310.php
http://git.postgresql.org/gitweb?p=postgresql.git;a=commit;h=64b057e6823655fb6c5d1f24a28f236b94dd6c54
https://bugzilla.redhat.com/show_bug.cgi?id=546621

CPE    75
cpe:/a:postgresql:postgresql:8.0.18
cpe:/a:postgresql:postgresql:8.0.17
cpe:/a:postgresql:postgresql:8.0.19
cpe:/a:postgresql:postgresql:8.2.9
...
CWE    1
CWE-189
OVAL    10
oval:org.secpod.oval:def:200002
oval:org.secpod.oval:def:200077
oval:org.secpod.oval:def:200085
oval:org.secpod.oval:def:200150
...

© SecPod Technologies