September 26, 2024: PostgreSQL 17 Released!

CVE-2005-1409

Public EXECUTE access is given to certain character conversion functions that are not designed to be safe against malicious arguments. This can cause at least a denial of service. A valid login is required to exploit this vulnerability.Note! See the announcement for special upgrade instructions.

Version Information

Affected Version Fixed In
8.0 8.0.3
7.4 7.4.8
7.3 7.3.10

For more information about PostgreSQL versioning, please visit the versioning page.

Reporting Security Vulnerabilities

If you wish to report a new security vulnerability in PostgreSQL, please send an email to security@postgresql.org.

For reporting non-security bugs, please see the Report a Bug page.