CVE Vulnerabilities

CVE-2009-4034

Published: Dec 15, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:P
RedHat/V2
3.6 LOW
AV:N/AC:H/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly handle a 0 character in a domain name in the subjects Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based PostgreSQL servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended client-hostname restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Affected Software

NameVendorStart VersionEnd Version
PostgresqlPostgresql7.4.1 (including)7.4.1 (including)
PostgresqlPostgresql7.4.2 (including)7.4.2 (including)
PostgresqlPostgresql7.4.3 (including)7.4.3 (including)
PostgresqlPostgresql7.4.4 (including)7.4.4 (including)
PostgresqlPostgresql7.4.5 (including)7.4.5 (including)
PostgresqlPostgresql7.4.6 (including)7.4.6 (including)
PostgresqlPostgresql7.4.7 (including)7.4.7 (including)
PostgresqlPostgresql7.4.8 (including)7.4.8 (including)
PostgresqlPostgresql7.4.9 (including)7.4.9 (including)
PostgresqlPostgresql7.4.10 (including)7.4.10 (including)
PostgresqlPostgresql7.4.11 (including)7.4.11 (including)
PostgresqlPostgresql7.4.12 (including)7.4.12 (including)
PostgresqlPostgresql7.4.13 (including)7.4.13 (including)
PostgresqlPostgresql7.4.14 (including)7.4.14 (including)
PostgresqlPostgresql7.4.15 (including)7.4.15 (including)
PostgresqlPostgresql7.4.16 (including)7.4.16 (including)
PostgresqlPostgresql7.4.17 (including)7.4.17 (including)
PostgresqlPostgresql7.4.18 (including)7.4.18 (including)
PostgresqlPostgresql7.4.19 (including)7.4.19 (including)
PostgresqlPostgresql7.4.20 (including)7.4.20 (including)
PostgresqlPostgresql7.4.21 (including)7.4.21 (including)
PostgresqlPostgresql7.4.22 (including)7.4.22 (including)
PostgresqlPostgresql7.4.23 (including)7.4.23 (including)
PostgresqlPostgresql7.4.24 (including)7.4.24 (including)
PostgresqlPostgresql7.4.25 (including)7.4.25 (including)
PostgresqlPostgresql7.4.26 (including)7.4.26 (including)
PostgresqlPostgresql8.0.0 (including)8.0.0 (including)
PostgresqlPostgresql8.0.1 (including)8.0.1 (including)
PostgresqlPostgresql8.0.2 (including)8.0.2 (including)
PostgresqlPostgresql8.0.3 (including)8.0.3 (including)
PostgresqlPostgresql8.0.4 (including)8.0.4 (including)
PostgresqlPostgresql8.0.5 (including)8.0.5 (including)
PostgresqlPostgresql8.0.6 (including)8.0.6 (including)
PostgresqlPostgresql8.0.7 (including)8.0.7 (including)
PostgresqlPostgresql8.0.8 (including)8.0.8 (including)
PostgresqlPostgresql8.0.9 (including)8.0.9 (including)
PostgresqlPostgresql8.0.10 (including)8.0.10 (including)
PostgresqlPostgresql8.0.11 (including)8.0.11 (including)
PostgresqlPostgresql8.0.12 (including)8.0.12 (including)
PostgresqlPostgresql8.0.13 (including)8.0.13 (including)
PostgresqlPostgresql8.0.14 (including)8.0.14 (including)
PostgresqlPostgresql8.0.15 (including)8.0.15 (including)
PostgresqlPostgresql8.0.16 (including)8.0.16 (including)
PostgresqlPostgresql8.0.17 (including)8.0.17 (including)
PostgresqlPostgresql8.0.18 (including)8.0.18 (including)
PostgresqlPostgresql8.0.19 (including)8.0.19 (including)
PostgresqlPostgresql8.0.20 (including)8.0.20 (including)
PostgresqlPostgresql8.0.21 (including)8.0.21 (including)
PostgresqlPostgresql8.0.22 (including)8.0.22 (including)
PostgresqlPostgresql8.1.0 (including)8.1.0 (including)
PostgresqlPostgresql8.1.1 (including)8.1.1 (including)
PostgresqlPostgresql8.1.2 (including)8.1.2 (including)
PostgresqlPostgresql8.1.3 (including)8.1.3 (including)
PostgresqlPostgresql8.1.4 (including)8.1.4 (including)
PostgresqlPostgresql8.1.5 (including)8.1.5 (including)
PostgresqlPostgresql8.1.6 (including)8.1.6 (including)
PostgresqlPostgresql8.1.7 (including)8.1.7 (including)
PostgresqlPostgresql8.1.8 (including)8.1.8 (including)
PostgresqlPostgresql8.1.9 (including)8.1.9 (including)
PostgresqlPostgresql8.1.10 (including)8.1.10 (including)
PostgresqlPostgresql8.1.11 (including)8.1.11 (including)
PostgresqlPostgresql8.1.12 (including)8.1.12 (including)
PostgresqlPostgresql8.1.13 (including)8.1.13 (including)
PostgresqlPostgresql8.1.14 (including)8.1.14 (including)
PostgresqlPostgresql8.1.15 (including)8.1.15 (including)
PostgresqlPostgresql8.1.16 (including)8.1.16 (including)
PostgresqlPostgresql8.1.17 (including)8.1.17 (including)
PostgresqlPostgresql8.1.18 (including)8.1.18 (including)
PostgresqlPostgresql8.2 (including)8.2 (including)
PostgresqlPostgresql8.2.1 (including)8.2.1 (including)
PostgresqlPostgresql8.2.2 (including)8.2.2 (including)
PostgresqlPostgresql8.2.3 (including)8.2.3 (including)
PostgresqlPostgresql8.2.4 (including)8.2.4 (including)
PostgresqlPostgresql8.2.5 (including)8.2.5 (including)
PostgresqlPostgresql8.2.6 (including)8.2.6 (including)
PostgresqlPostgresql8.2.7 (including)8.2.7 (including)
PostgresqlPostgresql8.2.8 (including)8.2.8 (including)
PostgresqlPostgresql8.2.9 (including)8.2.9 (including)
PostgresqlPostgresql8.2.10 (including)8.2.10 (including)
PostgresqlPostgresql8.2.11 (including)8.2.11 (including)
PostgresqlPostgresql8.2.12 (including)8.2.12 (including)
PostgresqlPostgresql8.2.13 (including)8.2.13 (including)
PostgresqlPostgresql8.2.14 (including)8.2.14 (including)
PostgresqlPostgresql8.3.1 (including)8.3.1 (including)
PostgresqlPostgresql8.3.2 (including)8.3.2 (including)
PostgresqlPostgresql8.3.3 (including)8.3.3 (including)
PostgresqlPostgresql8.3.4 (including)8.3.4 (including)
PostgresqlPostgresql8.3.5 (including)8.3.5 (including)
PostgresqlPostgresql8.3.6 (including)8.3.6 (including)
PostgresqlPostgresql8.3.7 (including)8.3.7 (including)
PostgresqlPostgresql8.3.8 (including)8.3.8 (including)
PostgresqlPostgresql8.4.1 (including)8.4.1 (including)
Postgresql-7.4Ubuntudapper*
Postgresql-8.0Ubuntudapper*
Postgresql-8.1Ubuntudapper*
Postgresql-8.2Ubuntuhardy*
Postgresql-8.3Ubuntuhardy*
Postgresql-8.3Ubuntuintrepid*
Postgresql-8.3Ubuntujaunty*
Postgresql-8.3Ubuntukarmic*
Postgresql-8.4Ubuntukarmic*

References