CVE-2009-0922

EUVD-2009-0919
PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified encoding, as demonstrated using mismatched encoding conversion requests.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
Affected Products (NVD)
VendorProductVersion
postgresqlpostgresql
7.4.24
postgresqlpostgresql
8.0.20
postgresqlpostgresql
8.1.16
postgresqlpostgresql
8.2.12
postgresqlpostgresql
8.3.6
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
postgresql-7.4
dapper
ignored
gutsy
dne
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
lucid
dne
maverick
dne
natty
dne
oneiric
dne
postgresql-8.0
dapper
ignored
gutsy
dne
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
lucid
dne
maverick
dne
natty
dne
oneiric
dne
postgresql-8.1
dapper
Fixed 8.1.17-0ubuntu0.6.06.1
released
gutsy
ignored
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
lucid
dne
maverick
dne
natty
dne
oneiric
dne
postgresql-8.2
dapper
dne
gutsy
ignored
hardy
ignored
intrepid
dne
jaunty
dne
karmic
dne
lucid
dne
maverick
dne
natty
dne
oneiric
dne
postgresql-8.3
dapper
dne
gutsy
dne
hardy
Fixed 8.3.7-0ubuntu8.04.1
released
intrepid
Fixed 8.3.7-0ubuntu8.10.1
released
jaunty
not-affected
karmic
not-affected
lucid
dne
maverick
dne
natty
dne
oneiric
dne
Common Weakness Enumeration
References