High severity7.5NVD Advisory· Published May 23, 2017· Updated May 13, 2026
CVE-2015-4054
CVE-2015-4054
Description
PgBouncer before 1.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by sending a password packet before a startup packet.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- github.com/pgbouncer/pgbouncer/commit/74d6e5f7de5ec736f71204b7b422af7380c19ac5nvdPatchThird Party Advisory
- github.com/pgbouncer/pgbouncer/commit/edab5be6665b9e8de66c25ba527509b229468573nvdPatchThird Party Advisory
- github.com/pgbouncer/pgbouncer/issues/42nvdExploitThird Party Advisory
- www.openwall.com/lists/oss-security/2015/05/22/5nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/74751nvdThird Party AdvisoryVDB Entry
- pgbouncer.github.io/changelog.htmlnvdRelease NotesThird Party Advisory
- security.gentoo.org/glsa/201701-24nvdThird Party Advisory
News mentions
0No linked articles in our index yet.