CVE-2009-0922
Publication date 17 March 2009
Last updated 24 July 2024
Ubuntu priority
PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified encoding, as demonstrated using mismatched encoding conversion requests.
Status
Package | Ubuntu Release | Status |
---|---|---|
postgresql-7.4 | ||
postgresql-8.0 | ||
postgresql-8.1 | ||
postgresql-8.2 | ||
postgresql-8.3 | ||
Notes
mdeslaur
the denial of service is only temporary, so impact isn't great. (should this be changed to "low priority"?) upstream patch replaces core dump due to stack overflow with core dump due to abort(), so doesn't fix temporary DoS see http://archives.postgresql.org//pgsql-bugs/2009-02/msg00190.php