← Vulnerability feed

Vulnerability record · CVE-2010-0442 · published 2 February 2010

CVE-2010-0442: Postgresql vulnerability

Postgresql · Postgresql

The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument, as demonstrated by a SELECT statement that contains a call to the substring function for a bit string, related to an "overflow."

6.5 CVSS 2.0 Medium EPSS 13% · top 3.7% CWE-189 · CWE-189
6.5CVSS 2.0 base score
13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
52References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument, as demonstrated by a SELECT statement that contains a call to the substring function for a bit string, related to an "overflow."

AV:N/AC:L/Au:S/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.postgresql.org/pgsql-committers/2010-01/msg00125.php Vendor Advisory
http://archives.postgresql.org/pgsql-hackers/2010-01/msg00634.php Vendor Advisory
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=567058 Third Party Advisory
http://git.postgresql.org/gitweb?p=postgresql.git%3Ba=commit%3Bh=75dea10196c31d98d98c0bafeeb576ae99c09b12 Vendor Advisory
http://git.postgresql.org/gitweb?p=postgresql.git%3Ba=commit%3Bh=b15087cb39ca9e4bde3c8920fcee3741045d2b83 Vendor Advisory
http://intevydis.blogspot.com/2010/01/postgresql-8023-bitsubstr-overflow.html Third Party Advisory
http://secunia.com/advisories/39566 Broken Link
http://secunia.com/advisories/39820 Broken Link
http://secunia.com/advisories/39939 Broken Link
http://securitytracker.com/id?1023510 Third Party AdvisoryVDB Entry
http://ubuntu.com/usn/usn-933-1 Third Party Advisory
http://www.debian.org/security/2010/dsa-2051 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2010:103 Broken Link
http://www.openwall.com/lists/oss-security/2010/01/27/5 Mailing ListThird Party Advisory
http://www.redhat.com/support/errata/RHSA-2010-0427.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2010-0428.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2010-0429.html Third Party Advisory
http://www.securityfocus.com/bid/37973 ExploitThird Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2010/1022 Permissions Required
http://www.vupen.com/english/advisories/2010/1197 Permissions Required
http://www.vupen.com/english/advisories/2010/1207 Permissions Required
http://www.vupen.com/english/advisories/2010/1221 Permissions Required
https://bugzilla.redhat.com/show_bug.cgi?id=559194 Issue TrackingThird Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=559259 Issue TrackingThird Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/55902 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9720 Third Party Advisory
http://archives.postgresql.org/pgsql-committers/2010-01/msg00125.php Vendor Advisory
http://archives.postgresql.org/pgsql-hackers/2010-01/msg00634.php Vendor Advisory
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=567058 Third Party Advisory
http://git.postgresql.org/gitweb?p=postgresql.git%3Ba=commit%3Bh=75dea10196c31d98d98c0bafeeb576ae99c09b12 Vendor Advisory
http://git.postgresql.org/gitweb?p=postgresql.git%3Ba=commit%3Bh=b15087cb39ca9e4bde3c8920fcee3741045d2b83 Vendor Advisory
http://intevydis.blogspot.com/2010/01/postgresql-8023-bitsubstr-overflow.html Third Party Advisory
http://secunia.com/advisories/39566 Broken Link
http://secunia.com/advisories/39820 Broken Link
http://secunia.com/advisories/39939 Broken Link
http://securitytracker.com/id?1023510 Third Party AdvisoryVDB Entry
http://ubuntu.com/usn/usn-933-1 Third Party Advisory
http://www.debian.org/security/2010/dsa-2051 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2010:103 Broken Link
http://www.openwall.com/lists/oss-security/2010/01/27/5 Mailing ListThird Party Advisory

Track CVE-2010-0442 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-1902Postgresql vulnerabilityPostgreSQL, 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 generates insecure temporary fi…EPSS 2.2%10.0CVE-2013-1903Postgresql permissions and access controls vulnerabilityPostgreSQL, possibly 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 incorrectly provides t…EPSS 2.2%10.0CVE-2007-3279Postgresql vulnerabilityPostgreSQL 8.1 and probably later versions, when the PL/pgSQL (plpgsql) language has been created, grants certain plpgsql privileges to the PUBLIC do…EPSS 2.6%10.0CVE-2002-1399Postgresql vulnerabilityUnknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknow…EPSS 1.8%9.8CVE-2015-0244Postgresql sql injection vulnerabilityPostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while …EPSS 4.4%9.8CVE-2015-3166Postgresql memory buffer overflow vulnerabilityThe snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does no…EPSS 4.6%9.8CVE-2019-10211Postgresql code injection vulnerabilityPostgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected di…EPSS 1.8%9.8CVE-2018-16850Postgresql sql injection vulnerabilitypostgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpo…EPSS 5.1%

Source: NIST National Vulnerability Database (record CVE-2010-0442), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.