CVE Database
/

CVE-2009-4034

Back to search

CVE-2009-4034

Published: Dec 15, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based PostgreSQL servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended client-hostname restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

VendorProductVersions

n/a

n/a

affected
n/a

References

61038
vdb-entry
x_refsource_OSVDB
HPSBMU02781
vendor-advisory
x_refsource_HP
FEDORA-2009-13363
vendor-advisory
x_refsource_FEDORA
SUSE-SR:2010:001
vendor-advisory
x_refsource_SUSE
FEDORA-2009-13381
vendor-advisory
x_refsource_FEDORA
1023325
vdb-entry
x_refsource_SECTRACK
MDVSA-2009:333
vendor-advisory
x_refsource_MANDRIVA
37334
vdb-entry
x_refsource_BID
ADV-2009-3519
vdb-entry
x_refsource_VUPEN
37663
third-party-advisory
x_refsource_SECUNIA
SSRT100617
vendor-advisory
x_refsource_HP

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now