CVE-2009-0922

Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 17 Mar 2009, 17:00
Last modified:07 Aug 2024, 04:57

Vulnerability Summary

Overall Risk (default)
medium
28/100
CVSS Score
4 MEDIUM
v2.0 (nvd)
EPSS Score
9.1% LOW
9% probability +0.45%
KEV
Not listed
Ransomware
No reports
Public exploits
4 found
Dark Web
Not detected

Timeline

17 Mar 2009, 17:00
Published
Vulnerability first disclosed
07 Aug 2024, 04:57
Last Modified
Vulnerability information updated

Description

PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified encoding, as demonstrated using mismatched encoding conversion requests.

CVSS Metrics

  • v2.0MEDIUMScore: 4AV:N/AC:L/Au:S/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 9.10% Percentile: 93%

Techniques & Countermeasures

  • CWE-399Resource Management Errors

    Weaknesses in this category are related to improper management of system resources.

Affected Systems

  • postgresqlpostgresql

    7.4.24 | 8.0.20 | 8.1.16 | 8.2.12 | 8.3.6

References (24)