CVE-2007-3278
PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host…
Does this matter?
Lower severity and a low EPSS score (1.26%). Track it; it rarely justifies an emergency change on its own.
Description
PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 1.26% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- postgresql/postgresql · debian/debian linux
- Source
- cve@mitre.org
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154Third Party Advisory
- http://osvdb.org/40899Broken Link
- http://secunia.com/advisories/28376Broken Link
- http://secunia.com/advisories/28437Broken Link
- http://secunia.com/advisories/28438Broken Link
- http://secunia.com/advisories/28445Broken Link
- http://secunia.com/advisories/28454Broken Link
- http://secunia.com/advisories/28477Broken Link
- http://secunia.com/advisories/28479Broken Link
- http://secunia.com/advisories/28679Broken Link
- http://secunia.com/advisories/29638Broken Link
- http://security.gentoo.org/glsa/glsa-200801-15.xmlThird Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-103197-1Broken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-200559-1Broken Link
- http://www.debian.org/security/2008/dsa-1460Third Party Advisory
- http://www.debian.org/security/2008/dsa-1463Third Party Advisory
- http://www.leidecker.info/pgshell/Having_Fun_With_PostgreSQL.txtThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:188Third Party Advisory
- http://www.portcullis.co.uk/uplds/whitepapers/Having_Fun_With_PostgreSQL.pdfThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0038.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0039.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0040.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/471541/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/471644/100/0/threadedThird Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/0109Permissions Required
- http://www.vupen.com/english/advisories/2008/1071/referencesPermissions Required
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35142Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10334Third Party Advisory
- https://usn.ubuntu.com/568-1/Third Party Advisory
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.