Pgbouncer · Pgbouncer · CVE-2015-4054
**Name of the Vulnerable Software and Affected Versions**
PgBouncer versions prior to 1.5.5
**Description**
The issue allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference and crash. This can be achieved by sending a password packet before a startup packet.
**Recommendations**
For versions prior to 1.5.5, update to version 1.5.5 or later to resolve the issue.