Back

MEDIUM

postgresql: MITM due improper x509_v3 CN validation during certificate verification

Published Jul 18, 2012

Description

PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host name is exactly 32 characters.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 18, 2012
Updated Aug 6, 2024
Reserved Jan 19, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Feb 27, 2012