CVE Vulnerabilities

CVE-2007-3278

Published: Jun 19, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1.

Affected Software

NameVendorStart VersionEnd Version
PostgresqlPostgresql7.3 (including)7.3.21 (excluding)
PostgresqlPostgresql7.4 (including)7.4.19 (excluding)
PostgresqlPostgresql8.0 (including)8.0.15 (excluding)
PostgresqlPostgresql8.1 (including)8.1.11 (excluding)
PostgresqlPostgresql8.2 (including)8.2.6 (excluding)
Red Hat Enterprise Linux 3RedHatrh-postgresql-0:7.3.21-1*
Red Hat Enterprise Linux 4RedHatpostgresql-0:7.4.19-1.el4_6.1*
Red Hat Enterprise Linux 5RedHatpostgresql-0:8.1.11-1.el5_1.1*
Red Hat Web Application Stack for RHEL 4RedHatpostgresql-0:8.1.11-1.el4s1.1*

References