4
CVSSv2

CVE-2012-2655

Published: 18/07/2012 Updated: 19/04/2013
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

PostgreSQL 8.3.x prior to 8.3.19, 8.4.x prior to 8.4.12, 9.0.x prior to 9.0.8, and 9.1.x prior to 9.1.4 allows remote authenticated users to cause a denial of service (server crash) by adding the (1) SECURITY DEFINER or (2) SET attributes to a procedural language's call handler.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

postgresql postgresql 8.3.13

postgresql postgresql 8.3.6

postgresql postgresql 8.3.4

postgresql postgresql 8.3.11

postgresql postgresql 8.3.8

postgresql postgresql 8.3.2

postgresql postgresql 8.3.1

postgresql postgresql 8.3.14

postgresql postgresql 8.3.17

postgresql postgresql 8.3.7

postgresql postgresql 8.3.5

postgresql postgresql 8.3.16

postgresql postgresql 8.3.15

postgresql postgresql 8.3.10

postgresql postgresql 8.3.9

postgresql postgresql 8.3

postgresql postgresql 8.3.12

postgresql postgresql 8.3.3

postgresql postgresql 8.3.18

postgresql postgresql 8.4.3

postgresql postgresql 8.4.4

postgresql postgresql 8.4

postgresql postgresql 8.4.2

postgresql postgresql 8.4.11

postgresql postgresql 8.4.1

postgresql postgresql 8.4.6

postgresql postgresql 8.4.9

postgresql postgresql 8.4.10

postgresql postgresql 8.4.5

postgresql postgresql 8.4.7

postgresql postgresql 8.4.8

postgresql postgresql 9.0

postgresql postgresql 9.0.1

postgresql postgresql 9.0.6

postgresql postgresql 9.0.7

postgresql postgresql 9.0.4

postgresql postgresql 9.0.5

postgresql postgresql 9.0.2

postgresql postgresql 9.0.3

postgresql postgresql 9.1

postgresql postgresql 9.1.1

postgresql postgresql 9.1.2

postgresql postgresql 9.1.3

Vendor Advisories

Synopsis Moderate: postgresql and postgresql84 security update Type/Severity Security Advisory: Moderate Topic Updated postgresql84 and postgresql packages that fix two security issuesare now available for Red Hat Enterprise Linux 5 and 6 respectivelyThe Red Hat Security Response Team has rated this update ...
PostgreSQL could be made to crash or incorrectly handle authentication ...
A flaw was found in the way the crypt() password hashing function from the optional PostgreSQL pgcrypto contrib module performed password transformation when used with the DES algorithm If the password string to be hashed contained the 0x80 byte value, the remainder of the string was ignored when calculating the hash, significantly reducing the pa ...