CVE-2006-5540
Title: Postgresql Denial of Service (DoS)
DoS
Proof Of Concept
No public PoC currently indexed for CVE-2006-5540.
CWE Category
NVD-CWE-noinfo
Published Date
Oct 26, 2006
Modified Date
Jun 16, 2026
Exploit Status
Not Found
Score
4.0
CVSS v2.0
Exploit Probability (EPSS)
1.93%
Vulnerability Summary
CVE-2006-5540: backend/parser/analyze.c in PostgreSQL 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) via certain aggregate functions in an UPDATE statement, which are not properly handled during a "MIN/MAX index optimization."
Impacted Vendors
Reference Links
ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc
http://projects.commandprompt.com/public/pgsql/changeset/25504
http://secunia.com/advisories/22562
http://secunia.com/advisories/22584
http://secunia.com/advisories/22606
http://secunia.com/advisories/22636
http://secunia.com/advisories/23048
http://secunia.com/advisories/23132
http://secunia.com/advisories/24094
http://secunia.com/advisories/24284
http://secunia.com/advisories/24577
http://securitytracker.com/id?1017115
http://support.avaya.com/elmodocs2/security/ASA-2007-117.htm
http://support.novell.com/techcenter/psdb/59650c03a8bc5ae310cd7898bd106ad2.html
http://www.mandriva.com/security/advisories?name=MDKSA-2006:194
http://www.novell.com/linux/security/advisories/2006_27_sr.html
http://www.postgresql.org/about/news.664
http://www.redhat.com/support/errata/RHSA-2007-0064.html
http://www.redhat.com/support/errata/RHSA-2007-0067.html
http://www.redhat.com/support/errata/RHSA-2007-0068.html
http://www.securityfocus.com/bid/20717
http://www.trustix.org/errata/2006/0059/
http://www.ubuntu.com/usn/usn-369-1
http://www.ubuntu.com/usn/usn-369-2
http://www.vupen.com/english/advisories/2006/4182
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11425
ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc
http://projects.commandprompt.com/public/pgsql/changeset/25504
http://secunia.com/advisories/22562
http://secunia.com/advisories/22584
http://secunia.com/advisories/22606
http://secunia.com/advisories/22636
http://secunia.com/advisories/23048
http://secunia.com/advisories/23132
http://secunia.com/advisories/24094
http://secunia.com/advisories/24284
http://secunia.com/advisories/24577
http://securitytracker.com/id?1017115
http://support.avaya.com/elmodocs2/security/ASA-2007-117.htm
http://support.novell.com/techcenter/psdb/59650c03a8bc5ae310cd7898bd106ad2.html
http://www.mandriva.com/security/advisories?name=MDKSA-2006:194
http://www.novell.com/linux/security/advisories/2006_27_sr.html
http://www.postgresql.org/about/news.664
http://www.redhat.com/support/errata/RHSA-2007-0064.html
http://www.redhat.com/support/errata/RHSA-2007-0067.html
http://www.redhat.com/support/errata/RHSA-2007-0068.html
http://www.securityfocus.com/bid/20717
http://www.trustix.org/errata/2006/0059/
http://www.ubuntu.com/usn/usn-369-1
http://www.ubuntu.com/usn/usn-369-2
http://www.vupen.com/english/advisories/2006/4182
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11425
CVSS v2.0
Source Entity
[email protected]
Severity
MEDIUM
4.0
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:L/Au:S/C:N/I:N/A:P
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2006-5540 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:L/Au:S/C:N/I:N/A:P
Affected Stack
No specific products linked.