CVE-2012-0867
Estado: ModificadaMedia (4.3)—
PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host name is exactly 32 characters.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.34%
- Percentil entre todas las CVEs puntuadas: 83
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (11)
Debian — Debian LinuxOpensuse Project — OpensusePostgresql — PostgresqlRedhat — Desktop WorkstationRedhat — Enterprise LinuxRedhat — Enterprise Linux DesktopRedhat — Enterprise Linux HPC NodeRedhat — Enterprise Linux ServerRedhat — Enterprise Linux Server AUSRedhat — Enterprise Linux Server EUSRedhat — Enterprise Linux Workstation
CWE
- CWE-20, CWE-295
Referencias
- http://lists.opensuse.org/opensuse-updates/2012-09/msg00060.html
- http://rhn.redhat.com/errata/RHSA-2012-0678.html
- http://secunia.com/advisories/49273
- http://www.debian.org/security/2012/dsa-2418
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:026
- http://www.postgresql.org/about/news/1377/
- http://www.postgresql.org/docs/8.4/static/release-8-4-11.html
- http://www.postgresql.org/docs/9.0/static/release-9-0-7.html
- http://www.postgresql.org/docs/9.1/static/release-9-1-3.html
- http://lists.opensuse.org/opensuse-updates/2012-09/msg00060.html
- http://rhn.redhat.com/errata/RHSA-2012-0678.html
- http://secunia.com/advisories/49273
- http://www.debian.org/security/2012/dsa-2418
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:026
- http://www.postgresql.org/about/news/1377/
- http://www.postgresql.org/docs/8.4/static/release-8-4-11.html
- http://www.postgresql.org/docs/9.0/static/release-9-0-7.html
- http://www.postgresql.org/docs/9.1/static/release-9-1-3.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-0867",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-07-18T23:55:01.827",
"references": [
{
"url": "http://lists.opensuse.org/opensuse-updates/2012-09/msg00060.html",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2012-0678.html",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/49273",
"source": "secalert@redhat.com"
},
{
"url": "http://www.debian.org/security/2012/dsa-2418",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2012:026",
"tags": [
"Broken Link"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.postgresql.org/about/news/1377/",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.postgresql.org/docs/8.4/static/release-8-4-11.html",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.postgresql.org/docs/9.0/static/release-9-0-7.html",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.postgresql.org/docs/9.1/static/release-9-1-3.html",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2012-09/msg00060.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2012-0678.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/49273",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2012/dsa-2418",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2012:026",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.postgresql.org/about/news/1377/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.postgresql.org/docs/8.4/static/release-8-4-11.html",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.postgresql.org/docs/9.0/static/release-9-0-7.html",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.postgresql.org/docs/9.1/static/release-9-1-3.html",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
},
{
"lang": "en",
"value": "CWE-295"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host name is exactly 32 characters."
},
{
"lang": "es",
"value": "PostgreSQL v8.4.x antes de v8.4.11, v9.0.x antes de v9.0.7, y v9.1.x antes de v9.1.3 trunca el nombre común a sólo 32 caracteres en la verificación de los certificados SSL, lo que permite a atacantes remotos falsificar conexiones cuando el nombre de host es exactamente de 32 caracteres."
}
],
"lastModified": "2026-06-16T23:38:25.007",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:opensuse_project:opensuse:12.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "06FD3E94-06C6-4C93-B6EB-442D1B5C62AD"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8F30CA60-0A82-45CD-8044-CE245393593D"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5C991F71-1E27-47A6-97DC-424FC3EF6011"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5740C7AA-1772-41D8-9851-3E3669CD8521"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "970338CD-A680-4DD0-BD27-459B0DDA4002"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A99C579D-44C0-40A4-A4EB-CBCF40D0C2FA"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3E9E57FA-5EAE-4698-992D-146C6310E0B8"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C66CDEC1-FB2E-49B7-A8BE-38E43C8ED652"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "87DF2937-9C51-4768-BAB1-901BCA636ADD"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "515C0ECD-2D95-4B6E-8E2F-DAF94E4A310F"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EA0EB754-7A71-40FA-9EAD-44914EB758C3"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1089D316-D5A3-4F2D-9E52-57FD626A1D06"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:postgresql:postgresql:9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2DD4DE67-9E3C-4F79-8AAB-344C1C46C618"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:9.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CCB718D2-97AA-4D61-AA4B-2216EEF55F67"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:9.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "605C06BF-54A0-40F8-A01E-8641B4A83035"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:9.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1F1F5B75-78D5-408E-8148-CA23DCED9CBB"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:9.0.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "88DE8C27-0E0A-4428-B25D-054D4FC6FEA8"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:9.0.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F609DDE4-0858-4F83-B8E6-7870196E21CB"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:9.0.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "349F02AF-013E-4264-9717-010293A3D6E4"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "036E8A89-7A16-411F-9D31-676313BB7244"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:redhat:desktop_workstation:5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B9F8A72C-443B-4FC8-9A9C-311A3ED94257"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D8B549B-E57B-4DFE-8A13-CAB06B5356B3"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "133AAFA7-AF42-4D7B-8822-AA2E85611BF5"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EE249E1B-A1FD-4E08-AA71-A0E1F10FFE97"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_hpc_node:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C2FAC325-6EEB-466D-9EBA-8ED4DBC9CFBF"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9BBCD86A-E6C7-4444-9D74-F861084090F0"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_server_aus:6.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AD6D0378-F0F4-4AAA-80AF-8287C790EC96"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_server_eus:6.2.z:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE3115B4-5DF0-415B-83D9-CC460AF75586"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E5ED5807-55B7-47C5-97A6-03233F4FBC3A"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:postgresql:postgresql:9.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4796DBEC-FF4F-4749-90D5-AD83D8B5E086"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:9.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "79108278-D644-4506-BD9C-F464C6E817B7"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:9.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "10CF0AA0-41CD-4D50-BA7A-BF8846115C95"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}