CVE-2009-0922

PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified encoding, as demonstrated using mismatched encoding conversion requests.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
postgresqlpostgresql
7.4.24
postgresqlpostgresql
8.0.20
postgresqlpostgresql
8.1.16
postgresqlpostgresql
8.2.12
postgresqlpostgresql
8.3.6
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
postgresql-7.4
oneiric
dne
natty
dne
maverick
dne
lucid
dne
karmic
dne
jaunty
dne
intrepid
dne
hardy
dne
gutsy
dne
dapper
ignored
postgresql-8.0
oneiric
dne
natty
dne
maverick
dne
lucid
dne
karmic
dne
jaunty
dne
intrepid
dne
hardy
dne
gutsy
dne
dapper
ignored
postgresql-8.1
oneiric
dne
natty
dne
maverick
dne
lucid
dne
karmic
dne
jaunty
dne
intrepid
dne
hardy
dne
gutsy
ignored
dapper
Fixed 8.1.17-0ubuntu0.6.06.1
released
postgresql-8.2
oneiric
dne
natty
dne
maverick
dne
lucid
dne
karmic
dne
jaunty
dne
intrepid
dne
hardy
ignored
gutsy
ignored
dapper
dne
postgresql-8.3
oneiric
dne
natty
dne
maverick
dne
lucid
dne
karmic
not-affected
jaunty
not-affected
intrepid
Fixed 8.3.7-0ubuntu8.10.1
released
hardy
Fixed 8.3.7-0ubuntu8.04.1
released
gutsy
dne
dapper
dne
Common Weakness Enumeration
References