PgBouncer 'add_database()' Function Denial of Service Vulnerability
BID:56371
Info
PgBouncer 'add_database()' Function Denial of Service Vulnerability
| Bugtraq ID: | 56371 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2012-4575 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2012 12:00AM |
| Updated: | Apr 13 2015 09:44PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
PgBouncer PgBouncer 1.5.2 |
| Not Vulnerable: |
PgBouncer PgBouncer 1.5.3 |
Discussion
PgBouncer 'add_database()' Function Denial of Service Vulnerability
PgBouncer is prone to a remote denial-of-service vulnerability.
Successful exploits may allow attackers to shutdown the server, denying service to legitimate users.
Versions prior to PgBouncer 1.5.3 are vulnerable.
PgBouncer is prone to a remote denial-of-service vulnerability.
Successful exploits may allow attackers to shutdown the server, denying service to legitimate users.
Versions prior to PgBouncer 1.5.3 are vulnerable.
Exploit / POC
PgBouncer 'add_database()' Function Denial of Service Vulnerability
An attacker may exploit this issue through readily available networking tools.
An attacker may exploit this issue through readily available networking tools.
Solution / Fix
PgBouncer 'add_database()' Function Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
PgBouncer 'add_database()' Function Denial of Service Vulnerability
References:
References:
- Bug 872527 - pgbouncer: DoS (pooler server shutdown) by adding database with lar (Bugzilla)
- Patch-add_database: fail gracefully if too long db name (Marko Kreen)
- PgBouncer Homepage (PgBouncer)
- pgbouncer-dev / NEWS (PgBouncer)