CVE-2015-0241: Debian Linux

High severity, CVSS 8.8. EPSS: 5.5% chance of exploitation in the next 30 days.

The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a (1) large number of digits when processing a numeric formatting template, which triggers a buffer over-read, or (2) crafted timestamp formatting template, which triggers a buffer overflow.

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • PostgreSQL PostgreSQL: before 9.0.19 (fixed in 9.0.19); from 9.1.0, before 9.1.15 (fixed in 9.1.15); from 9.2.0, before 9.2.10 (fixed in 9.2.10); from 9.3.0, before 9.3.6 (fixed in 9.3.6); from 9.4.0, before 9.4.1 (fixed in 9.4.1)

Published 2020-01-27. Last modified 2026-06-17.