Secunia Security Advisory - A vulnerability has been reported in PostgreSQL, which can be exploited by malicious people to cause a DoS (Denial of Service).
be396e54094a3c8e882a2044aed3652c75c3ecad09219d7175e62f934825ee66
TITLE:
PostgreSQL Multiple Connections Denial of Service Vulnerability
SECUNIA ADVISORY ID:
SA18419
VERIFY ADVISORY:
https://secunia.com/advisories/18419/
CRITICAL:
Less critical
IMPACT:
DoS
WHERE:
>From local network
SOFTWARE:
PostgreSQL 8.x
https://secunia.com/product/4587/
DESCRIPTION:
A vulnerability has been reported in PostgreSQL, which can be
exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to an error in the handling of
multiple concurrent connections. This can be exploited to shutdown
the postmaster process.
Successful exploitation causes a situation where new connections
can't be established until the service is manually restarted.
The vulnerability has been reported in versions 8.0.0 through 8.0.5
and 8.1.0 through 8.1.1. This only affects the Microsoft Windows
platform.
SOLUTION:
Update to version 8.0.6 or 8.1.2.
https://www.postgresql.org/ftp/
PROVIDED AND/OR DISCOVERED BY:
The vendor credits Yoshiyuki Asaba.
ORIGINAL ADVISORY:
https://archives.postgresql.org/pgsql-announce/2006-01/msg00001.php
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
https://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
https://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------