PostgreSQL: Stack-based buffer overflow by processing certain tokens from SQL query string when intarray module enabled
Published Feb 2, 2011
6.5
MEDIUMCVSS 2.0
EPSS 4.62%
Description
Buffer overflow in the gettoken function in contrib/intarray/_int_bool.c in the intarray array module in PostgreSQL 9.0.x before 9.0.3, 8.4.x before 8.4.7, 8.3.x before 8.3.14, and 8.2.x before 8.2.20 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via integers with a large number of digits to unspecified functions.
Affected products
No data.
Configuration 1
- 8.3
- 8.3.1
- 8.3.2
- 8.3.3
- 8.3.4
- 8.3.5
- 8.3.6
- 8.3.7
- 8.3.8
- 8.3.9
- 8.3.10
- 8.3.11
- 8.3.12
- 8.3.13
Configuration 2
- 9.0
- 9.0.1
- 9.0.2
Configuration 3
- 8.4
- 8.4.1
- 8.4.2
- 8.4.3
- 8.4.4
- 8.4.5
- 8.4.6
Configuration 4
- 8.2
- 8.2.1
- 8.2.2
- 8.2.3
- 8.2.4
- 8.2.5
- 8.2.6
- 8.2.7
- 8.2.8
- 8.2.9
- 8.2.10
- 8.2.11
- 8.2.12
- 8.2.13
- 8.2.14
- 8.2.15
- 8.2.16
- 8.2.17
- 8.2.18
- 8.2.19
No data.
Red Hat Enterprise Linux 4
postgresql-0:7.4.30-1.el4_8.2
Fixed · RHSA-2011:0197
Red Hat Enterprise Linux 5
postgresql-0:8.1.23-1.el5_6.1
Fixed · RHSA-2011:0197
Red Hat Enterprise Linux 5
postgresql84-0:8.4.7-1.el5_6.1
Fixed · RHSA-2011:0198
Red Hat Enterprise Linux 6
postgresql-0:8.4.7-1.el6_0.1
Fixed · RHSA-2011:0197
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | postgresql-0:7.4.30-1.el4_8.2 | Fixed | RHSA-2011:0197 |
| Red Hat Enterprise Linux 5 | postgresql-0:8.1.23-1.el5_6.1 | Fixed | RHSA-2011:0197 |
| Red Hat Enterprise Linux 5 | postgresql84-0:8.4.7-1.el5_6.1 | Fixed | RHSA-2011:0198 |
| Red Hat Enterprise Linux 6 | postgresql-0:8.4.7-1.el6_0.1 | Fixed | RHSA-2011:0197 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:S/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.62% (0.04621) | 91.41th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.62% (0.04621) | 90.48th | v5 (v2026.06.15) |
| Dec 14, 2025 | 3.22% (0.03220) | 86.62th | v4 (v2025.03.14) |
| Aug 4, 2025 | 5.30% (0.05303) | 89.65th | v4 (v2025.03.14) |
| Mar 30, 2025 | 3.96% (0.03959) | 87.29th | v4 (v2025.03.14) |
| Mar 29, 2025 | 12.76% (0.12761) | 89.99th | v4 (v2025.03.14) |
| Mar 17, 2025 | 3.96% (0.03959) | 87.60th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.88% (0.01880) | 88.93th | v3 (v2023.03.01) |
| Nov 8, 2023 | 1.88% (0.01880) | 87.09th | v3 (v2023.03.01) |
| Sep 22, 2023 | 1.45% (0.01452) | 85.10th | v3 (v2023.03.01) |
| Aug 2, 2023 | 1.37% (0.01373) | 84.53th | v3 (v2023.03.01) |
| Apr 16, 2023 | 1.20% (0.01201) | 83.10th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.19% (0.01185) | 82.87th | v3 (v2023.03.01) |
| Mar 6, 2023 | 6.82% (0.06823) | 92.16th | v2 (v2022.01.01) |
| Apr 1, 2022 | 6.82% (0.06823) | 91.42th | v2 (v2022.01.01) |
| Feb 4, 2022 | 6.82% (0.06823) | 79.56th | v2 (v2022.01.01) |
References (33)
- http://git.postgresql.org/gitweb?p=postgresql.git%3Ba=commitdiff%3Bh=7ccb6dc2d3e266a551827bb99179708580f72431 x_refsource_CONFIRM
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 x_refsource_CONFIRM
- http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053817.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053888.html vendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=134124585221119&w=2 vendor-advisoryx_refsource_HP
- http://osvdb.org/70740 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/43144 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/43154 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/43155 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/43187 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/43188 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/43240 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2011/dsa-2157 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:021 vendor-advisoryx_refsource_MANDRIVA
- http://www.postgresql.org/about/news.1289 x_refsource_CONFIRM
- http://www.postgresql.org/support/security x_refsource_CONFIRM
- http://www.redhat.com/support/errata/RHSA-2011-0197.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2011-0198.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/46084 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-1058-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2011/0262 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2011/0278 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0283 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0287 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0299 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0303 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0349 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2010-4015 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=664402 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65060 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2010-4015
- https://www.cve.org/CVERecord?id=CVE-2010-4015
Change history (0)
No recorded changes yet.