PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified encoding, as demonstrated using mismatched encoding conversion requests.
2009-03-17T17:30:00.187
2025-04-09T00:30:58.490
Deferred
CVSSv2: 4.0 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:N/A:P
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | postgresql | postgresql | 7.4.24 | Yes |
Application | postgresql | postgresql | 8.0.20 | Yes |
Application | postgresql | postgresql | 8.1.16 | Yes |
Application | postgresql | postgresql | 8.2.12 | Yes |
Application | postgresql | postgresql | 8.3.6 | Yes |