4
CVSSv2

CVE-2009-3229

Published: 17/09/2009 Updated: 10/10/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 358
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

The core server component in PostgreSQL 8.4 prior to 8.4.1, 8.3 prior to 8.3.8, and 8.2 prior to 8.2.14 allows remote authenticated users to cause a denial of service (backend shutdown) by "re-LOAD-ing" libraries from a certain plugins directory.

Vulnerable Product Search on Vulmon Subscribe to Product

postgresql postgresql 8.4

postgresql postgresql 8.3

postgresql postgresql 8.3.7

postgresql postgresql 8.2.1

postgresql postgresql 8.2.13

postgresql postgresql 8.3.6

postgresql postgresql 8.3.5

postgresql postgresql 8.2.12

postgresql postgresql 8.2.3

postgresql postgresql 8.2.2

postgresql postgresql 8.2.10

postgresql postgresql 8.2.7

postgresql postgresql 8.3.2

postgresql postgresql 8.3.1

postgresql postgresql 8.2.5

postgresql postgresql 8.2

postgresql postgresql 8.2.8

postgresql postgresql 8.3.4

postgresql postgresql 8.3.3

postgresql postgresql 8.2.4

postgresql postgresql 8.2.11

postgresql postgresql 8.2.6

postgresql postgresql 8.2.9

Vendor Advisories

It was discovered that PostgreSQL could be made to unload and reload an already loaded module by using the LOAD command A remote authenticated attacker could exploit this to cause a denial of service This issue did not affect Ubuntu 606 LTS (CVE-2009-3229) ...
Several vulnerabilities have been discovered in PostgreSQL, an SQL database system The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-3229 Authenticated users can shut down the backend server by re-LOAD-ing libraries in $libdir/plugins, if any libraries are present there (The old stable distribution (etc ...