CVE Vulnerabilities

CVE-2007-6601

Improper Authentication

Published: Jan 09, 2008 | Modified: Jan 18, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2007-3278.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Postgresql Postgresql 7.3.0 (including) 7.3.21 (excluding)
Postgresql Postgresql 7.4.0 (including) 7.4.19 (excluding)
Postgresql Postgresql 8.0.0 (including) 8.0.15 (excluding)
Postgresql Postgresql 8.1.0 (including) 8.1.11 (excluding)
Postgresql Postgresql 8.2.0 (including) 8.2.6 (excluding)
Postgresql Postgresql 8.2 (including) 8.2 (including)

Potential Mitigations

References