LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2012-0867

CVE-2012-0867

CVSS 4.3 · MEDIUM

Summary

PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host name is exactly 32 characters.

CVSS 2.0 breakdown

Base score4.3 (MEDIUM)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Attack vectorNETWORK
Attack complexityMEDIUM
ConfidentialityNONE
IntegrityPARTIAL
AvailabilityNONE

Weakness type (CWE)

Affected products

Opensuse_project opensusePostgresql postgresqlDebian debian linuxRedhat desktop workstationRedhat enterprise linuxRedhat enterprise linux desktopRedhat enterprise linux hpc nodeRedhat enterprise linux serverRedhat enterprise linux server ausRedhat enterprise linux server eusRedhat enterprise linux workstation
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD. NVD last modified 2026-04-29. Always verify against the vendor advisory before acting.

Scroll to Top