PT-2007-4557 · Postgresql+1 · Postgresql+1

CVE-2007-3278

·

Publicado

2007-06-19

·

Atualizado

2023-02-24

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PostgreSQL versions 8.1 and later
Description The issue allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries. This is possible when local trust authentication is enabled and the Database Link library (dblink) is installed. Attackers can exploit this by using a dblink host parameter that proxies the connection from 127.0.0.1.
Recommendations For PostgreSQL versions 8.1 and later, consider disabling the Database Link library (dblink) or restricting its use to prevent exploitation. Additionally, review and restrict local trust authentication settings to minimize the risk of unauthorized access.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-3278
DSA-1460-1
DSA-1463-1
RHSA-2008:0038
RHSA-2008:0039
RHSA-2008:0040
RHSA-2008_0038

Produtos afetados

Postgresql
Red Hat