PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers with no privileges on a large object to overwrite the entire contents of the object, resulting in a denial of service.
| Software | From | Fixed in |
|---|---|---|
| postgresql / postgresql | 9.6 | 9.6.4 |
| postgresql / postgresql | 9.5 | 9.5.8 |
| postgresql / postgresql | 9.4 | 9.4.13 |
| debian / debian_linux | 8.0 | 8.0.x |
| debian / debian_linux | 9.0 | 9.0.x |