CVE Vulnerabilities

CVE-2007-6601

Improper Authentication

Published: Jan 09, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2007-3278.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
PostgresqlPostgresql7.3.0 (including)7.3.21 (excluding)
PostgresqlPostgresql7.4.0 (including)7.4.19 (excluding)
PostgresqlPostgresql8.0.0 (including)8.0.15 (excluding)
PostgresqlPostgresql8.1.0 (including)8.1.11 (excluding)
PostgresqlPostgresql8.2.0 (including)8.2.6 (excluding)
PostgresqlPostgresql8.2 (including)8.2 (including)
Red Hat Enterprise Linux 3RedHatrh-postgresql-0:7.3.21-1*
Red Hat Enterprise Linux 4RedHatpostgresql-0:7.4.19-1.el4_6.1*
Red Hat Enterprise Linux 5RedHatpostgresql-0:8.1.11-1.el5_1.1*
Red Hat Web Application Stack for RHEL 4RedHatpostgresql-0:8.1.11-1.el4s1.1*
Postgresql-8.1Ubuntudapper*
Postgresql-8.1Ubuntuedgy*
Postgresql-8.1Ubuntufeisty*
Postgresql-8.1Ubuntugutsy*
Postgresql-8.2Ubuntufeisty*
Postgresql-8.2Ubuntugutsy*
Postgresql-8.2Ubuntuhardy*

Potential Mitigations

References