CVE-2009-4034
Summary
| CVE | CVE-2009-4034 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-12-15 18:30:01 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based PostgreSQL servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended client-hostname restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:N/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Postgresql | Postgresql | 7.4.1 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.10 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.11 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.12 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.13 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.14 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.15 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.16 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.17 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.18 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.19 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.2 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.20 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.21 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.22 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.23 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.24 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.25 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.26 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.3 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.4 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.5 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.6 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.7 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.8 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.0 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.10 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.11 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.12 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.13 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.14 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.15 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.16 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.17 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.18 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.19 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.20 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.21 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.22 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.6 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.8 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.0 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.10 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.11 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.12 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.13 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.14 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.15 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.16 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.17 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.18 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.6 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.8 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.10 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.11 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.12 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.13 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.14 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.6 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.8 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.6 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.8 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PostgreSQL: Documentation: Manuals: PostgreSQL 8.4: Release 8.2.15 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Patch, Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| '[security bulletin] HPSBMU02781 SSRT100617 rev.1 - HP Network Node Manager i (NNMi) for HP-UX, Linux' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| SecurityTracker.com Archives - PostgreSQL NULL Character Flaw in Certificate Processing Lets Remote Users Spoof Certficiates | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Webmail- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| PostgreSQL: Documentation: Manuals: PostgreSQL 8.4: Release 8.3.9 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Patch, Vendor Advisory |
| PostgreSQL: Documentation: Manuals: PostgreSQL 8.4: Release 8.1.19 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Patch, Vendor Advisory |
| osvdb.org/61038 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Support / Security / Advisories / / MDVSA-2009:333 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| PostgreSQL: Documentation: Manuals: PostgreSQL 8.4: Release 8.0.23 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Patch, Vendor Advisory |
| [SECURITY] Fedora 11 Update: postgresql-8.3.9-1.fc11 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:001 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| wiki.rpath.com/wiki/Advisories:rPSA-2010-0012 | af854a3a-2127-422b-91ae-364da2661108 | wiki.rpath.com | |
| PostgreSQL: Documentation: Manuals: PostgreSQL 8.4: Release 7.4.27 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Patch, Vendor Advisory |
| PostgreSQL NULL Character CA SSL Certificate Validation Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| PostgreSQL: Security Information | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Vendor Advisory |
| PostgreSQL SSL Certificate Processing and Privilege Escalation Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| PostgreSQL: Documentation: Manuals: PostgreSQL 8.4: Release 8.4.2 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Patch, Vendor Advisory |
| [SECURITY] Fedora 12 Update: postgresql-8.4.2-1.fc12 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2010-01-07 | Mark Cox | This issue is only security-relevant in PostgreSQL versions 8.4 and later as previous versions did not compare the connection host name with the certificate CommonName at all. Client certificate authentication was introduced in version 8.4. Red Hat Enterprise Linux 5 and earlier provided PostgreSQL versions 8.1.x and earlier, and are thus not affected by this issue. |
There are currently no legacy QID mappings associated with this CVE.