CVE-2009-3229
Summary
| CVE | CVE-2009-3229 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-09-17 10:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, and 8.2 before 8.2.14 allows remote authenticated users to cause a denial of service (backend shutdown) by "re-LOAD-ing" libraries from a certain plugins directory. |
Risk And Classification
Primary CVSS: v2.0 4 from [email protected]
AV:N/AC:L/Au:S/C:N/I:N/A:P
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:S/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Postgresql | Postgresql | 8.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.10 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.11 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.12 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.13 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.6 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.8 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.6 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.4 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 10 Update: postgresql-8.3.8-1.fc10 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:017 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| '[security bulletin] HPSBMU02781 SSRT100617 rev.1 - HP Network Node Manager i (NNMi) for HP-UX, Linux' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Debian update for postgresql - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Bug 522092 – CVE-2009-3229 postgresql: authenticated user server DoS via plugin re-LOAD-ing | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| PostgreSQL Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| USN-834-1: PostgreSQL vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| [SECURITY] Fedora 11 Update: postgresql-8.3.8-1.fc11 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| PostgreSQL: Documentation: Manuals: PostgreSQL 8.3: Release 8.3.8 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | |
| Fedora update for postgresql - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| wiki.rpath.com/wiki/Advisories:rPSA-2010-0012 | af854a3a-2127-422b-91ae-364da2661108 | wiki.rpath.com | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| PostgreSQL: Security Information | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Vendor Advisory |
| Security Advisory SA36800 - Ubuntu update for postgresql - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| PostgreSQL Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Debian -- Security Information -- DSA-1900-1 postgresql-7.4, postgresql-8.1, postgresql-8.3, postgresql-8.4 | af854a3a-2127-422b-91ae-364da2661108 | www.us.debian.org | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:016 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-09-24 | Tomas Hoger | Not vulnerable. This issue did not affect the versions of PostgreSQL as shipped with Red Hat Enterprise Linux 3, 4, or 5. In PostgreSQL versions prior to 8.2, only database administrator was able to LOAD additional plugins and use it to cause server crash. However, this does not bypass trust boundary, so its not a security flaw for older PostgreSQL versions. Additionally, no plugins are shipped in Red Hat PostgreSQL packages by default. This issue was addressed in Red Hat Application Stack v2 via https://rhn.redhat.com/errata/RHSA-2009-1461.html . |
There are currently no legacy QID mappings associated with this CVE.