MEDIUM · 4.3

CVE-2012-0867

PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof conne...

Vulnerability Description

PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host name is exactly 32 characters.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
Opensuse ProjectOpensuse12.2
PostgresqlPostgresql8.4
DebianDebian Linux6.0
RedhatDesktop Workstation5
RedhatEnterprise Linux5.0
RedhatEnterprise Linux Desktop5.0
RedhatEnterprise Linux Hpc Node6.0
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Server Aus6.2
RedhatEnterprise Linux Server Eus6.2.z
RedhatEnterprise Linux Workstation6.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-0867?

CVE-2012-0867 is a vulnerability with a CVSS score of 4.3 (MEDIUM). PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof conne...

How severe is CVE-2012-0867?

CVE-2012-0867 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-0867?

Check the references section above for vendor advisories and patch information. Affected products include: Opensuse Project Opensuse, Postgresql Postgresql, Debian Debian Linux, Redhat Desktop Workstation, Redhat Enterprise Linux.