CVE Vulnerabilities

CVE-2009-4034

Published: Dec 15, 2009 | Modified: Oct 10, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly handle a 0 character in a domain name in the subjects Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based PostgreSQL servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended client-hostname restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Affected Software

Name Vendor Start Version End Version
Postgresql Postgresql 7.4.16 7.4.16
Postgresql Postgresql 8.1.10 8.1.10
Postgresql Postgresql 8.1.6 8.1.6
Postgresql Postgresql 8.2.9 8.2.9
Postgresql Postgresql 8.0.7 8.0.7
Postgresql Postgresql 8.0.2 8.0.2
Postgresql Postgresql 8.1.15 8.1.15
Postgresql Postgresql 8.1.7 8.1.7
Postgresql Postgresql 8.3.6 8.3.6
Postgresql Postgresql 8.4.1 8.4.1
Postgresql Postgresql 8.2.10 8.2.10
Postgresql Postgresql 8.0.22 8.0.22
Postgresql Postgresql 7.4.24 7.4.24
Postgresql Postgresql 8.2.4 8.2.4
Postgresql Postgresql 7.4.22 7.4.22
Postgresql Postgresql 7.4.21 7.4.21
Postgresql Postgresql 8.0.17 8.0.17
Postgresql Postgresql 8.0.10 8.0.10
Postgresql Postgresql 7.4.19 7.4.19
Postgresql Postgresql 8.2.11 8.2.11
Postgresql Postgresql 8.1.13 8.1.13
Postgresql Postgresql 8.0.12 8.0.12
Postgresql Postgresql 8.2.12 8.2.12
Postgresql Postgresql 7.4.15 7.4.15
Postgresql Postgresql 8.0.9 8.0.9
Postgresql Postgresql 8.0.15 8.0.15
Postgresql Postgresql 7.4.1 7.4.1
Postgresql Postgresql 8.2.2 8.2.2
Postgresql Postgresql 8.3.3 8.3.3
Postgresql Postgresql 8.0.0 8.0.0
Postgresql Postgresql 8.1.0 8.1.0
Postgresql Postgresql 8.1.3 8.1.3
Postgresql Postgresql 7.4.14 7.4.14
Postgresql Postgresql 7.4.26 7.4.26
Postgresql Postgresql 7.4.6 7.4.6
Postgresql Postgresql 8.3.2 8.3.2
Postgresql Postgresql 7.4.23 7.4.23
Postgresql Postgresql 7.4.11 7.4.11
Postgresql Postgresql 8.0.18 8.0.18
Postgresql Postgresql 8.2.5 8.2.5
Postgresql Postgresql 8.0.3 8.0.3
Postgresql Postgresql 7.4.7 7.4.7
Postgresql Postgresql 8.1.9 8.1.9
Postgresql Postgresql 7.4.17 7.4.17
Postgresql Postgresql 7.4.3 7.4.3
Postgresql Postgresql 8.2.1 8.2.1
Postgresql Postgresql 8.3.1 8.3.1
Postgresql Postgresql 8.1.14 8.1.14
Postgresql Postgresql 7.4.25 7.4.25
Postgresql Postgresql 7.4.9 7.4.9
Postgresql Postgresql 7.4.5 7.4.5
Postgresql Postgresql 7.4.18 7.4.18
Postgresql Postgresql 8.3.5 8.3.5
Postgresql Postgresql 8.0.20 8.0.20
Postgresql Postgresql 8.3.8 8.3.8
Postgresql Postgresql 8.0.8 8.0.8
Postgresql Postgresql 7.4.8 7.4.8
Postgresql Postgresql 8.2.7 8.2.7
Postgresql Postgresql 8.0.6 8.0.6
Postgresql Postgresql 8.1.11 8.1.11
Postgresql Postgresql 8.2.6 8.2.6
Postgresql Postgresql 7.4.4 7.4.4
Postgresql Postgresql 8.0.16 8.0.16
Postgresql Postgresql 8.3.7 8.3.7
Postgresql Postgresql 8.1.17 8.1.17
Postgresql Postgresql 8.0.13 8.0.13
Postgresql Postgresql 8.1.18 8.1.18
Postgresql Postgresql 8.1.4 8.1.4
Postgresql Postgresql 8.0.1 8.0.1
Postgresql Postgresql 8.1.8 8.1.8
Postgresql Postgresql 8.3.4 8.3.4
Postgresql Postgresql 7.4.12 7.4.12
Postgresql Postgresql 8.0.19 8.0.19
Postgresql Postgresql 8.1.1 8.1.1
Postgresql Postgresql 8.1.12 8.1.12
Postgresql Postgresql 8.1.5 8.1.5
Postgresql Postgresql 8.0.21 8.0.21
Postgresql Postgresql 7.4.10 7.4.10
Postgresql Postgresql 8.1.16 8.1.16
Postgresql Postgresql 8.2.3 8.2.3
Postgresql Postgresql 8.0.4 8.0.4
Postgresql Postgresql 8.0.5 8.0.5
Postgresql Postgresql 7.4.20 7.4.20
Postgresql Postgresql 8.0.14 8.0.14
Postgresql Postgresql 8.2.8 8.2.8
Postgresql Postgresql 8.2.13 8.2.13
Postgresql Postgresql 8.2 8.2
Postgresql Postgresql 7.4.2 7.4.2
Postgresql Postgresql 8.0.11 8.0.11
Postgresql Postgresql 8.2.14 8.2.14
Postgresql Postgresql 7.4.13 7.4.13
Postgresql Postgresql 8.1.2 8.1.2

References