« Volver al listado

CVE-2009-0922

Estado: ModificadaMedia (4)—💥 Exploit

PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified encoding, as demonstrated using mismatched encoding conversion requests.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

💥 Exploits públicos

Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-0922",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-03-17T17:30:00.187",
  "references": [
    {
      "url": "http://archives.postgresql.org//pgsql-bugs/2009-02/msg00176.php",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.postgresql.org/pgsql-bugs/2009-02/msg00172.php",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=517405",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=134124585221119&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/34453",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/35100",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-66-258808-1",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020455.1-1",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://wiki.rpath.com/Advisories:rPSA-2009-0086",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:079",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2009/03/11/4",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.postgresql.org/about/news.1065",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2009-1067.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/503598/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/34090",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1021860",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/0767",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/1316",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=488156",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10874",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6252",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00810.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00843.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.postgresql.org//pgsql-bugs/2009-02/msg00176.php",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://archives.postgresql.org/pgsql-bugs/2009-02/msg00172.php",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=517405",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=134124585221119&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/34453",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/35100",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-66-258808-1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020455.1-1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://wiki.rpath.com/Advisories:rPSA-2009-0086",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:079",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2009/03/11/4",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.postgresql.org/about/news.1065",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2009-1067.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/503598/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/34090",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1021860",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/0767",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/1316",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=488156",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10874",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6252",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00810.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00843.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-399"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified encoding, as demonstrated using mismatched encoding conversion requests."
    },
    {
      "lang": "es",
      "value": "PostgreSQL en versiones anteriores a 8.3.7, 8.2.13, 8.1.17, 8.0.21 y 7.4.25 permite a usuarios remotos autenticados provocar una denegación de servicio (consumo de pila y caída) desencadenando un fallo en la conversión de un mensaje de error localizado en el cifrado para un cliente especificado, como se demuestra usando peticiones de conversión de codificación no coincidentes."
    }
  ],
  "lastModified": "2026-06-16T23:06:06.700",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:postgresql:postgresql:7.4.24:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4394564D-131D-41C8-AE3A-BFF44779F27B"
            },
            {
              "criteria": "cpe:2.3:a:postgresql:postgresql:8.0.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3CD7F8CA-09B3-4038-B8B0-2D62A77F2478"
            },
            {
              "criteria": "cpe:2.3:a:postgresql:postgresql:8.1.16:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B903334-2F67-4725-8277-6913E03BEFC3"
            },
            {
              "criteria": "cpe:2.3:a:postgresql:postgresql:8.2.12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC8C96F7-7F85-4E47-A05F-15E3C70AF583"
            },
            {
              "criteria": "cpe:2.3:a:postgresql:postgresql:8.3.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "74857259-30C7-422D-A24D-BE1E33F09466"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "vendorComments": [
    {
      "comment": "This issue has been addressed in Red Hat\nEnterprise Linux 4 and 5 via:\nhttps://rhn.redhat.com/errata/RHSA-2009-1484.html\n\nand in Red Hat Application Stack v2 via:\nhttps://rhn.redhat.com/errata/RHSA-2009-1067.html",
      "lastModified": "2009-10-08T00:00:00",
      "organization": "Red Hat"
    }
  ],
  "evaluatorComment": "Per: https://bugzilla.redhat.com/show_bug.cgi?id=488156\r\n\r\n\"PostgreSQL allows remote authenticated users to cause a momentary denial\r\nof service (crash due to stack consumption) when there is a failure to\r\nconvert a localized error message to the client-specified encoding.\r\nIn releases 8.3.6, 8.2.12, 8.1.16. 8.0.20, and 7.4.24, a trivial\r\nmisconfiguration is sufficient to provoke a crash.  In older releases\r\nit is necessary to select a locale and client encoding for which\r\nspecific messages fail to translate, and so a given installation may or\r\nmay not be vulnerable depending on the administrator-determined locale\r\nsetting.\r\n\r\nReleases 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 are secure against\r\nall known variants of this issue.\"",
  "sourceIdentifier": "cve@mitre.org"
}