CVE-2012-2655: Medium severity PostgreSQL postgresql vulnerability
PostgreSQL 8.3.x before 8.3.19, 8.4.x before 8.4.12, 9.0.x before 9.0.8, and 9.1.x before 9.1.4 allows remote authenticated users to cause a denial of service (server crash) by adding the (1) SECURITY DEFINER or (2) SET attributes to a procedural language's call handler.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2655?
CVE-2012-2655 is classified as a denial of service vulnerability that can lead to a server crash.
How do I fix CVE-2012-2655?
To fix CVE-2012-2655, you should upgrade PostgreSQL to version 8.3.19, 8.4.12, 9.0.8, or 9.1.4 or later.
Who is affected by CVE-2012-2655?
CVE-2012-2655 affects PostgreSQL versions 8.3.x prior to 8.3.19, 8.4.x prior to 8.4.12, 9.0.x prior to 9.0.8, and 9.1.x prior to 9.1.4.
What kind of attack can be executed using CVE-2012-2655?
An authenticated remote user can exploit CVE-2012-2655 to trigger a denial of service condition by using certain procedural language attributes.
Is CVE-2012-2655 an exploit for database servers?
Yes, CVE-2012-2655 specifically targets PostgreSQL database servers, allowing attackers to crash the server.