Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-1170

21
FAUCET Score

CVE-2010-1170 describes a vulnerability in the PL/Tcl implementation of PostgreSQL versions 7.4 through 8.4.4 and 9.0 Beta before 9.0 Beta 2. This flaw allows remote authenticated users with database-creation privileges to execute arbitrary Tcl code. The vulnerability stems from PL/Tcl loading code from the pltcl_modules table without proper ownership and permission checks. The vulnerability has a CVSS score of 6.0, indicating a medium severity. It requires network access and authenticated user privileges, but has medium attack complexity. Successful exploitation could lead to partial compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion is minimal, with only one mention, and there is no media coverage for this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
7.4CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:7.4:*:*:*:*:*:*:*
7.4.1CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:7.4.1:*:*:*:*:*:*:*
7.4.2CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:7.4.2:*:*:*:*:*:*:*
7.4.3CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:7.4.3:*:*:*:*:*:*:*
7.4.4CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:7.4.4:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.0MEDIUM

AV:N/AC:M/Au:S/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
SINGLE
Exploitability Score
6.8
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
2.89%
Probability of exploitation in next 30 days
EPSS Percentile
85.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0289 is in the 92nd percentile among its peer group of 1,428 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: rh-postgresql-0:7.3.21-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: postgresql-0:7.4.29-1.el4_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: postgresql-0:8.1.21-1.el5_5.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: postgresql84-0:8.4.4-1.el5_5.1
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: postgresql

Vendor Advisories (1)

redhatCVE-2010-1170Moderate

PostgreSQL: PL/Tcl Intended restriction bypass

May 17, 2010

References

lists.fedoraproject.org / pipermail/package-announce/2010-May/041559.html
lists.fedoraproject.org / pipermail/package-announce/2010-May/041579.html
lists.fedoraproject.org / pipermail/package-announce/2010-May/041591.html
lists.opensuse.org / opensuse-security-announce/2010-08/msg00001.html
marc.info
osvdb.org / 64757
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/39815
secunia.com / advisories/39820
secunia.com / advisories/39845
Vendor Advisory
secunia.com / advisories/39898
secunia.com / advisories/39939
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10510
debian.org / security/2010/dsa-2051
mandriva.com / security/advisories
openwall.com / lists/oss-security/2010/05/20/5
postgresql.org / about/news.1203
Vendor Advisory
postgresql.org / docs/current/static/release-7-4-29.html
postgresql.org / docs/current/static/release-8-0-25.html
postgresql.org / docs/current/static/release-8-1-21.html
postgresql.org / docs/current/static/release-8-2-17.html
postgresql.org / docs/current/static/release-8-3-11.html
postgresql.org / docs/current/static/release-8-4-4.html
postgresql.org / support/security
redhat.com / support/errata/RHSA-2010-0427.html
redhat.com / support/errata/RHSA-2010-0428.html
redhat.com / support/errata/RHSA-2010-0429.html
redhat.com / support/errata/RHSA-2010-0430.html
securityfocus.com / bid/40215
securitytracker.com / id
vupen.com / english/advisories/2010/1167
PatchVendor Advisory
vupen.com / english/advisories/2010/1182
vupen.com / english/advisories/2010/1197
vupen.com / english/advisories/2010/1198
vupen.com / english/advisories/2010/1207
vupen.com / english/advisories/2010/1221