See how pgbouncer project compares to other vendors in security performance
A denial of service flaw was found in the way pgbouncer, a lightweight connection pooler for PostgreSQL, performed processing of client requests attempting to add new database(s) with large name(s). A remote attacker could use this flaw to cause pooler server shutdown.
Relevant upstream patch: [1] http://git.postgresql.org/gitweb/?p=pgbouncer.git;a=commitdiff;h=4b92112b820830b30cd7bc91bef3dd8f35305525
References: [2] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=692103