← All CVEs

CVE-2009-0922

medium · 4

PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified encoding, as demonstrated using mismatched encoding conversion requests.

4
CVSS
10.2%
EPSS (exploit prob.)
95th
EPSS percentile
2009-03-17
Published

AV:N/AC:L/Au:S/C:N/I:N/A:P

Weaknesses

CWE-399

Affected products

VendorProductAffected versions
postgresqlpostgresql7.4.24
postgresqlpostgresql8.0.20
postgresqlpostgresql8.1.16
postgresqlpostgresql8.2.12
postgresqlpostgresql8.3.6

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-0922