Description
Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Remediation
References
Related Vulnerabilities
WordPress Plugin SEO Redirection-301 Redirect Manager Cross-Site Request Forgery (8.9)
PHP Use of Externally-Controlled Format String Vulnerability (CVE-2010-2950)
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2020-11057)
WordPress Plugin PickPlugins Product Slider for WooCommerce Unspecified Vulnerability (1.13.23)
WordPress Plugin WooCommerce Anti-Fraud Security Bypass (3.2)