CVE-2007-6601
The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2007-3278.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 1.57% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- postgresql/postgresql · debian/debian linux · fedoraproject/fedora
- Source
- cve@mitre.org
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154Broken Link
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00000.htmlBroken Link
- http://secunia.com/advisories/28359Not Applicable, Vendor Advisory
- http://secunia.com/advisories/28376Not Applicable
- http://secunia.com/advisories/28437Not Applicable
- http://secunia.com/advisories/28438Not Applicable
- http://secunia.com/advisories/28445Not Applicable
- http://secunia.com/advisories/28454Not Applicable
- http://secunia.com/advisories/28455Not Applicable
- http://secunia.com/advisories/28464Not Applicable
- http://secunia.com/advisories/28477Not Applicable
- http://secunia.com/advisories/28479Not Applicable
- http://secunia.com/advisories/28679Not Applicable
- http://secunia.com/advisories/28698Not Applicable
- http://secunia.com/advisories/29638Not Applicable
- http://security.gentoo.org/glsa/glsa-200801-15.xmlThird Party Advisory
- http://securitytracker.com/id?1019157Broken Link, Third Party Advisory, VDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-103197-1Broken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-200559-1Broken Link
- http://www.debian.org/security/2008/dsa-1460Third Party Advisory
- http://www.debian.org/security/2008/dsa-1463Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:004Broken Link
- http://www.postgresql.org/about/news.905Broken Link
- http://www.redhat.com/support/errata/RHSA-2008-0038.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0039.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0040.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/485864/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/486407/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/27163Patch, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/0061Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.