CVE-2012-0867
published 2012-07-18CVE-2012-0867: PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.34%
81.7th percentile
PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host name is exactly 32 characters.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| opensuse_project | opensuse | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| redhat | desktop_workstation | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_ubuntu6.5MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2012-02-28·CVSS 6.5
CVE-2012-0867 [MEDIUM] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: Several security issues were fixed in PostgreSQL.
It was discovered that PostgreSQL incorrectly checked permissions on
functions called by a trigger. An attacker could attach a trigger to a
table they owned and possibly escalate privileges. (CVE-2012-0866)
It was discovered that PostgreSQL incorrectly truncated SSL certificate
name checks to 32 characters. If a host name was exactly 32 characters,
this issue could be exploited by an attacker to spoof the SSL certificate.
This issue affected Ubuntu 10.04 LTS, Ubuntu 10.10, Ubuntu 11.04 and
Ubuntu 11.10. (CVE-2012-0867)
It was discovered that the PostgreSQL pg_dump utility incorrectly filtered
line breaks in object names. An attacker could create object names that
execute arbitrary SQL commands
Red Hat
postgresql: MITM due improper x509_v3 CN validation during certificate verification
vendor_redhat·2012-02-27·CVSS 4.3
CVE-2012-0867 [MEDIUM] postgresql: MITM due improper x509_v3 CN validation during certificate verification
postgresql: MITM due improper x509_v3 CN validation during certificate verification
PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host name is exactly 32 characters.
Package: postgresql (Red Hat Enterprise Linux 4) - Will not fix
Package: postgresql (Red Hat Enterprise Linux 5) - Not affected
GHSA
GHSA-r7m2-9mgg-wfjc: PostgreSQL 8
ghsa_unreviewed·2022-05-17
CVE-2012-0867 [MEDIUM] CWE-20 GHSA-r7m2-9mgg-wfjc: PostgreSQL 8
PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host name is exactly 32 characters.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0866 CVE-2012-0867 CVE-2012-0868 postgresql various flaws [fedora-all]
bugzilla·2012-02-27·CVSS 6.5
CVE-2012-0866 [MEDIUM] CVE-2012-0866 CVE-2012-0867 CVE-2012-0868 postgresql various flaws [fedora-all]
CVE-2012-0866 CVE-2012-0867 CVE-2012-0868 postgresql various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=secu
Bugzilla
CVE-2012-0867 postgresql: MITM due improper x509_v3 CN validation during certificate verification
bugzilla·2012-02-27·CVSS 4.3
CVE-2012-0867 [MEDIUM] CVE-2012-0867 postgresql: MITM due improper x509_v3 CN validation during certificate verification
CVE-2012-0867 postgresql: MITM due improper x509_v3 CN validation during certificate verification
A security flaw was found in the way PostgreSQL performed SSL certificate verification (only 32 characters from Common Name field of a particular certificate were recognized and verified), when SSL support was enabled. A rogue PostgreSQL server, able to obtain a carefully-crafted certificate, signed by a Certificate Authority trusted by PostgreSQL client, could use that certificate to conduct man-in-the-middle attack and potentially confuse PostgreSQL client into accepting it by mistake.
References:
[1] http://www.postgresql.org/support/security/
Discussion:
This issue affects the version of the postgresql84 package, as shipped with Red Hat Enterprise Linux 5.
--
This issue affects the v
http://lists.opensuse.org/opensuse-updates/2012-09/msg00060.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0678.htmlhttp://secunia.com/advisories/49273http://www.debian.org/security/2012/dsa-2418http://www.mandriva.com/security/advisories?name=MDVSA-2012:026http://www.postgresql.org/about/news/1377/http://www.postgresql.org/docs/8.4/static/release-8-4-11.htmlhttp://www.postgresql.org/docs/9.0/static/release-9-0-7.htmlhttp://www.postgresql.org/docs/9.1/static/release-9-1-3.htmlhttp://lists.opensuse.org/opensuse-updates/2012-09/msg00060.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0678.htmlhttp://secunia.com/advisories/49273http://www.debian.org/security/2012/dsa-2418http://www.mandriva.com/security/advisories?name=MDVSA-2012:026http://www.postgresql.org/about/news/1377/http://www.postgresql.org/docs/8.4/static/release-8-4-11.htmlhttp://www.postgresql.org/docs/9.0/static/release-9-0-7.htmlhttp://www.postgresql.org/docs/9.1/static/release-9-1-3.html
2012-07-18
Published