VulnerabilityModified
CVE-2009-3231
The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
MEDIUM 6.8EPSS 7.57%
Does this matter?
Lower severity and a low EPSS score (7.57%). Track it; it rarely justifies an emergency change on its own.
Description
The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 7.57% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- postgresql/postgresql · opensuse/opensuse · suse/linux enterprise · suse/linux enterprise server · fedoraproject/fedora · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.htmlMailing List
- http://marc.info/?l=bugtraq&m=134124585221119&w=2Mailing List
- http://secunia.com/advisories/36660Broken Link, Vendor Advisory
- http://secunia.com/advisories/36727Broken Link, Vendor Advisory
- http://secunia.com/advisories/36800Broken Link
- http://secunia.com/advisories/36837Broken Link
- http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0012Broken Link
- http://www.postgresql.org/docs/8.3/static/release-8-3-8.htmlRelease Notes
- http://www.postgresql.org/support/security.htmlBroken Link, Vendor Advisory
- http://www.securityfocus.com/archive/1/509917/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/36314Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-834-1Third Party Advisory
- http://www.us.debian.org/security/2009/dsa-1900Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=522084Issue Tracking, Patch
- https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00305.htmlMailing List
- https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00307.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.htmlMailing List
- http://marc.info/?l=bugtraq&m=134124585221119&w=2Mailing List
- http://secunia.com/advisories/36660Broken Link, Vendor Advisory
- http://secunia.com/advisories/36727Broken Link, Vendor Advisory
- http://secunia.com/advisories/36800Broken Link
- http://secunia.com/advisories/36837Broken Link
- http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0012Broken Link
- http://www.postgresql.org/docs/8.3/static/release-8-3-8.htmlRelease Notes
- http://www.postgresql.org/support/security.htmlBroken Link, Vendor Advisory
- http://www.securityfocus.com/archive/1/509917/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/36314Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-834-1Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.