[Forgot Password]
Login  Register Subscribe

23631

 
 

115038

 
 

96174

 
 

909

 
 

78077

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2010-0733

Date: (C)2010-03-19   (M)2017-09-22
 
CVSS Score: 3.5Access Vector: NETWORK
Exploitability Subscore: 6.8Access Complexity: MEDIUM
Impact Subscore: 2.9Authentication: SINGLE_INSTANCE
 Confidentiality: NONE
 Integrity: NONE
 Availability: PARTIAL











Integer overflow in src/backend/executor/nodeHash.c in PostgreSQL 8.4.1 and earlier, and 8.5 through 8.5alpha2, allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with many LEFT JOIN clauses, related to certain hashtable size calculations.

Reference:
BID-38619
SECUNIA-39820
ADV-2010-1197
RHSA-2010:0427
RHSA-2010:0428
RHSA-2010:0429
SUSE-SR:2010:014
http://www.openwall.com/lists/oss-security/2010/03/09/2
http://www.openwall.com/lists/oss-security/2010/03/16/10
http://archives.postgresql.org/pgsql-bugs/2009-10/msg00277.php
http://archives.postgresql.org/pgsql-bugs/2009-10/msg00289.php
http://archives.postgresql.org/pgsql-bugs/2009-10/msg00310.php
http://git.postgresql.org/gitweb?p=postgresql.git;a=commit;h=64b057e6823655fb6c5d1f24a28f236b94dd6c54
https://bugzilla.redhat.com/show_bug.cgi?id=546621

CPE    75
cpe:/a:postgresql:postgresql:8.0.18
cpe:/a:postgresql:postgresql:8.0.17
cpe:/a:postgresql:postgresql:8.0.19
cpe:/a:postgresql:postgresql:8.2.9
...
CWE    1
CWE-189
OVAL    10
oval:org.secpod.oval:def:300895
oval:org.secpod.oval:def:500481
oval:org.secpod.oval:def:201891
oval:org.secpod.oval:def:200085
...

© 2013 SecPod Technologies