CVE-2012-2655

PostgreSQL 8.3.x before 8.3.19, 8.4.x before 8.4.12, 9.0.x before 9.0.8, and 9.1.x before 9.1.4 allows remote authenticated users to cause a denial of service (server crash) by adding the (1) SECURITY DEFINER or (2) SET attributes to a procedural language's call handler.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:postgresql:postgresql:8.3:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.3.1:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.3.2:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.3.3:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.3.4:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.3.5:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.3.6:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.3.7:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.3.8:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.3.9:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.3.10:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.3.11:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.3.12:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.3.13:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.3.14:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.3.15:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.3.16:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.3.17:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.3.18:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:postgresql:postgresql:8.4:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.1:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.2:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.3:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.4:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.5:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.6:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.7:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.8:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.9:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.10:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.4.11:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:postgresql:postgresql:9.0:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.0.1:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.0.2:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.0.3:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.0.4:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.0.5:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.0.6:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.0.7:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:postgresql:postgresql:9.1:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.1.1:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.1.2:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:9.1.3:*:*:*:*:*:*:*

History

21 Nov 2024, 01:39

Type Values Removed Values Added
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082258.html - () http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082258.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082292.html - () http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082292.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082294.html - () http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082294.html -
References () http://lists.opensuse.org/opensuse-updates/2012-09/msg00102.html - () http://lists.opensuse.org/opensuse-updates/2012-09/msg00102.html -
References () http://lists.opensuse.org/opensuse-updates/2012-10/msg00013.html - () http://lists.opensuse.org/opensuse-updates/2012-10/msg00013.html -
References () http://lists.opensuse.org/opensuse-updates/2012-10/msg00024.html - () http://lists.opensuse.org/opensuse-updates/2012-10/msg00024.html -
References () http://rhn.redhat.com/errata/RHSA-2012-1037.html - () http://rhn.redhat.com/errata/RHSA-2012-1037.html -
References () http://secunia.com/advisories/50718 - () http://secunia.com/advisories/50718 -
References () http://www.debian.org/security/2012/dsa-2491 - () http://www.debian.org/security/2012/dsa-2491 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2012:092 - () http://www.mandriva.com/security/advisories?name=MDVSA-2012:092 -
References () http://www.postgresql.org/about/news/1398/ - Vendor Advisory () http://www.postgresql.org/about/news/1398/ - Vendor Advisory

Information

Published : 2012-07-18 23:55

Updated : 2024-11-21 01:39


NVD link : CVE-2012-2655

Mitre link : CVE-2012-2655

CVE.ORG link : CVE-2012-2655


JSON object : View

Products Affected

postgresql

  • postgresql
CWE
CWE-399

Resource Management Errors