CVE Vulnerabilities

CVE-2000-1199

Published: Aug 31, 2001 | Modified: Dec 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.

Affected Software

Name Vendor Start Version End Version
Postgresql Postgresql 6.3.2 (including) 6.3.2 (including)
Postgresql Postgresql 6.5.3 (including) 6.5.3 (including)

References