CVE-2012-2655

Modified
Published: 18 Jul 2012, 23:00
Last modified:06 Aug 2024, 19:42

Vulnerability Summary

Overall Risk (default)
low
16/100
CVSS Score
4 MEDIUM
v2.0 (nvd)
EPSS Score
1.41% LOW
1% probability -0.02%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Jul 2012, 23:00
Published
Vulnerability first disclosed
06 Aug 2024, 19:42
Last Modified
Vulnerability information updated

Description

PostgreSQL 8.3.x before 8.3.19, 8.4.x before 8.4.12, 9.0.x before 9.0.8, and 9.1.x before 9.1.4 allows remote authenticated users to cause a denial of service (server crash) by adding the (1) SECURITY DEFINER or (2) SET attributes to a procedural language's call handler.

CVSS Metrics

  • v2.0MEDIUMScore: 4AV:N/AC:L/Au:S/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 1.41% Percentile: 81%

Techniques & Countermeasures

  • CWE-399Resource Management Errors

    Weaknesses in this category are related to improper management of system resources.

Affected Systems

  • postgresqlpostgresql

    8.3 | 8.3.1 | 8.3.2 | 8.3.3 | 8.3.4 | 8.3.5 | 8.3.6 | 8.3.7 | 8.3.8 | 8.3.9 | 8.3.10 | 8.3.11 | 8.3.12 | 8.3.13 | 8.3.14 | 8.3.15 | 8.3.16 | 8.3.17 | 8.3.18 | 8.4 | 8.4.1 | 8.4.2 | 8.4.3 | 8.4.4 | 8.4.5 | 8.4.6 | 8.4.7 | 8.4.8 | 8.4.9 | 8.4.10 | 8.4.11 | 9.0 | 9.0.1 | 9.0.2 | 9.0.3 | 9.0.4 | 9.0.5 | 9.0.6 | 9.0.7 | 9.1 | 9.1.1 | 9.1.2 | 9.1.3

References (11)