REDHAT-BUG-872527: Medium severity debounce vulnerability
A denial of service flaw was found in the way pgbouncer, a lightweight connection pooler for PostgreSQL, performed processing of client requests attempting to add new database(s) with large name(s). A remote attacker could use this flaw to cause pooler server shutdown.
Relevant upstream patch: [1] http://git.postgresql.org/gitweb/?p=pgbouncer.git;a=commitdiff;h=4b92112b820830b30cd7bc91bef3dd8f35305525
References: [2] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=692103
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-872527?
The severity of REDHAT-BUG-872527 is classified as denial of service.
How do I fix REDHAT-BUG-872527?
To fix REDHAT-BUG-872527, apply the relevant upstream patch provided for PgBouncer.
Who is affected by REDHAT-BUG-872527?
REDHAT-BUG-872527 affects the PgBouncer connection pooler used with PostgreSQL.
What causes the issue in REDHAT-BUG-872527?
The issue in REDHAT-BUG-872527 is caused by how PgBouncer handles client requests for large database names.
Can REDHAT-BUG-872527 be exploited remotely?
Yes, REDHAT-BUG-872527 can be exploited remotely by an attacker to cause the pooler server to shut down.