PT-2007-4557 · Postgresql+1 · Postgresql+1
CVE-2007-3278
·
Publicado
2007-06-19
·
Atualizado
2023-02-24
CVSS v2.0
6.9
Média
| Vetor | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PostgreSQL versions 8.1 and later
Description
The issue allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries. This is possible when local trust authentication is enabled and the Database Link library (dblink) is installed. Attackers can exploit this by using a dblink host parameter that proxies the connection from 127.0.0.1.
Recommendations
For PostgreSQL versions 8.1 and later, consider disabling the Database Link library (dblink) or restricting its use to prevent exploitation. Additionally, review and restrict local trust authentication settings to minimize the risk of unauthorized access.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Postgresql
Red Hat