CVE-2015-0242: Debian Linux

High severity, CVSS 8.8. EPSS: 5.1% chance of exploitation in the next 30 days.

Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1, when running on a Windows system, allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a floating point number with a large precision, as demonstrated by using the to_char function.

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • PostgreSQL PostgreSQL: before 9.0.19 (fixed in 9.0.19); from 9.1.0, before 9.1.15 (fixed in 9.1.15); from 9.2.0, before 9.2.10 (fixed in 9.2.10); from 9.3.0, before 9.3.6 (fixed in 9.3.6); from 9.4.0, before 9.4.1 (fixed in 9.4.1)

Published 2020-01-27. Last modified 2026-06-17.