PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host name is exactly 32 characters.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T18:38:14.829Z
Reserved: 2012-01-19T00:00:00
Link: CVE-2012-0867

No data.

Status : Deferred
Published: 2012-07-18T23:55:01.827
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-0867
