CVE-2015-4054: Null Pointer Dereference
Published May 23, 2017
·Updated
PgBouncer before 1.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by sending a password packet before a startup packet.
Affected Software
1 affected component
PgBouncer PgBouncer<=1.5.4
Remediation
Event History
May 23, 2017
CVE Published
via MITRE·03:56 AM
Data Sourced
via MITRE·03:56 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4054?
CVE-2015-4054 is classified as a denial of service vulnerability that allows attackers to crash the PgBouncer service.
2
How do I fix CVE-2015-4054?
To mitigate CVE-2015-4054, upgrade PgBouncer to version 1.5.5 or later.
3
What versions of PgBouncer are affected by CVE-2015-4054?
CVE-2015-4054 affects PgBouncer versions prior to 1.5.5.
4
Can CVE-2015-4054 be exploited remotely?
Yes, CVE-2015-4054 can be exploited remotely by sending malformed packets.
5
What type of attack does CVE-2015-4054 enable?
CVE-2015-4054 enables a denial of service attack that can crash the service.