National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

CVE-2009-0922 Detail

Current Description

PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified encoding, as demonstrated using mismatched encoding conversion requests.

Source:  MITRE      Last Modified:  03/17/2009      View Analysis Description

Evaluator Description

Per: https://bugzilla.redhat.com/show_bug.cgi?id=488156 "PostgreSQL allows remote authenticated users to cause a momentary denial of service (crash due to stack consumption) when there is a failure to convert a localized error message to the client-specified encoding. In releases 8.3.6, 8.2.12, 8.1.16. 8.0.20, and 7.4.24, a trivial misconfiguration is sufficient to provoke a crash. In older releases it is necessary to select a locale and client encoding for which specific messages fail to translate, and so a given installation may or may not be vulnerable depending on the administrator-determined locale setting. Releases 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 are secure against all known variants of this issue."

Quick Info

CVE Dictionary Entry:
CVE-2009-0922
Original release date:
03/17/2009
Last revised:
09/28/2017
Source:
US-CERT/NIST

Impact

CVSS Severity (version 2.0):
CVSS v2 Base Score:
4.0 MEDIUM
Vector:
(AV:N/AC:L/Au:S/C:N/I:N/A:P) (legend)
Impact Subscore:
2.9
Exploitability Subscore:
8.0
CVSS Version 2 Metrics:
Access Vector:
Network exploitable
Access Complexity:
Low
Authentication:
Required to exploit
Impact Type:
Allows disruption of service

Vendor Statements (disclaimer)

Official Statement from Red Hat (10/08/2009)

This issue has been addressed in Red Hat Enterprise Linux 4 and 5 via: https://rhn.redhat.com/errata/RHSA-2009-1484.html and in Red Hat Application Stack v2 via: https://rhn.redhat.com/errata/RHSA-2009-1067.html

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.

Hyperlink Resource Type Source Name
http://archives.postgresql.org//pgsql-bugs/2009-02/msg00176.php Exploit External Source MLIST [pgsql-bugs] 20090227 Re: BUG #4680: Server crashed if using wrong (mismatch) conversion functions
http://archives.postgresql.org/pgsql-bugs/2009-02/msg00172.php Exploit External Source MLIST [pgsql-bugs] 20090227 BUG #4680: Server crashed if using wrong (mismatch) conversion functions
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=517405 External Source CONFIRM http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=517405
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html External Source SUSE SUSE-SR:2009:009
http://marc.info/?l=bugtraq&m=134124585221119&w=2 External Source HP SSRT100617
http://sunsolve.sun.com/search/document.do?assetkey=1-66-258808-1 External Source SUNALERT 258808
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020455.1-1 External Source SUNALERT 1020455
http://wiki.rpath.com/Advisories:rPSA-2009-0086 External Source CONFIRM http://wiki.rpath.com/Advisories:rPSA-2009-0086
http://www.mandriva.com/security/advisories?name=MDVSA-2009:079 External Source MANDRIVA MDVSA-2009:079
http://www.openwall.com/lists/oss-security/2009/03/11/4 External Source MLIST [oss-security] 20090311 CVE request -- postgresql
http://www.postgresql.org/about/news.1065 Patch; Vendor Advisory External Source CONFIRM http://www.postgresql.org/about/news.1065
http://www.redhat.com/support/errata/RHSA-2009-1067.html External Source REDHAT RHSA-2009:1067
http://www.securityfocus.com/archive/1/archive/1/503598/100/0/threaded External Source BUGTRAQ 20090519 rPSA-2009-0086-1 postgresql postgresql-contrib postgresql-server
http://www.securityfocus.com/bid/34090 Exploit; Patch External Source BID 34090
http://www.securitytracker.com/id?1021860 External Source SECTRACK 1021860
http://www.vupen.com/english/advisories/2009/0767 Patch; Vendor Advisory External Source VUPEN ADV-2009-0767
http://www.vupen.com/english/advisories/2009/1316 Patch; Vendor Advisory External Source VUPEN ADV-2009-1316
https://bugzilla.redhat.com/show_bug.cgi?id=488156 External Source CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=488156
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10874 External Source OVAL oval:org.mitre.oval:def:10874
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6252 External Source OVAL oval:org.mitre.oval:def:6252
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00810.html External Source FEDORA FEDORA-2009-2927
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00843.html External Source FEDORA FEDORA-2009-2959

References to Check Content

Identifier:
oval:org.mitre.oval:def:10874
Check System:
http://oval.mitre.org/XMLSchema/oval-definitions-5
Hyperlink:
http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10874
Identifier:
oval:org.mitre.oval:def:6252
Check System:
http://oval.mitre.org/XMLSchema/oval-definitions-5
Hyperlink:
http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6252

Technical Details

Vulnerability Type (View All)

  • Resource Management Errors (CWE-399)

Change History 5 change records found - show changes