PgBouncer before 1.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by sending a password packet before a startup packet.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Pgbouncer | Pgbouncer | * | 1.5.4 (including) |
| Pgbouncer | Ubuntu | precise | * |
| Pgbouncer | Ubuntu | trusty | * |
| Pgbouncer | Ubuntu | upstream | * |
| Pgbouncer | Ubuntu | utopic | * |
| Pgbouncer | Ubuntu | vivid | * |