CVE-2007-6601

The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2007-3278.
References
Link Resource
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154 Broken Link
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154 Broken Link
http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00000.html Broken Link
http://secunia.com/advisories/28359 Not Applicable Vendor Advisory
http://secunia.com/advisories/28376 Not Applicable
http://secunia.com/advisories/28437 Not Applicable
http://secunia.com/advisories/28438 Not Applicable
http://secunia.com/advisories/28445 Not Applicable
http://secunia.com/advisories/28454 Not Applicable
http://secunia.com/advisories/28455 Not Applicable
http://secunia.com/advisories/28464 Not Applicable
http://secunia.com/advisories/28477 Not Applicable
http://secunia.com/advisories/28479 Not Applicable
http://secunia.com/advisories/28679 Not Applicable
http://secunia.com/advisories/28698 Not Applicable
http://secunia.com/advisories/29638 Not Applicable
http://security.gentoo.org/glsa/glsa-200801-15.xml Third Party Advisory
http://securitytracker.com/id?1019157 Broken Link Third Party Advisory VDB Entry
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103197-1 Broken Link
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200559-1 Broken Link
http://www.debian.org/security/2008/dsa-1460 Third Party Advisory
http://www.debian.org/security/2008/dsa-1463 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2008:004 Broken Link
http://www.postgresql.org/about/news.905 Broken Link
http://www.redhat.com/support/errata/RHSA-2008-0038.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2008-0039.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2008-0040.html Third Party Advisory
http://www.securityfocus.com/archive/1/485864/100/0/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/archive/1/486407/100/0/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/27163 Patch Third Party Advisory VDB Entry
http://www.vupen.com/english/advisories/2008/0061 Permissions Required
http://www.vupen.com/english/advisories/2008/0109 Permissions Required Third Party Advisory
http://www.vupen.com/english/advisories/2008/1071/references Permissions Required
https://exchange.xforce.ibmcloud.com/vulnerabilities/39500 Third Party Advisory VDB Entry
https://issues.rpath.com/browse/RPL-1768 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11127 Broken Link
https://usn.ubuntu.com/568-1/ Broken Link
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00397.html Mailing List Third Party Advisory
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00469.html Mailing List Third Party Advisory
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154 Broken Link
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154 Broken Link
http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00000.html Broken Link
http://secunia.com/advisories/28359 Not Applicable Vendor Advisory
http://secunia.com/advisories/28376 Not Applicable
http://secunia.com/advisories/28437 Not Applicable
http://secunia.com/advisories/28438 Not Applicable
http://secunia.com/advisories/28445 Not Applicable
http://secunia.com/advisories/28454 Not Applicable
http://secunia.com/advisories/28455 Not Applicable
http://secunia.com/advisories/28464 Not Applicable
http://secunia.com/advisories/28477 Not Applicable
http://secunia.com/advisories/28479 Not Applicable
http://secunia.com/advisories/28679 Not Applicable
http://secunia.com/advisories/28698 Not Applicable
http://secunia.com/advisories/29638 Not Applicable
http://security.gentoo.org/glsa/glsa-200801-15.xml Third Party Advisory
http://securitytracker.com/id?1019157 Broken Link Third Party Advisory VDB Entry
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103197-1 Broken Link
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200559-1 Broken Link
http://www.debian.org/security/2008/dsa-1460 Third Party Advisory
http://www.debian.org/security/2008/dsa-1463 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2008:004 Broken Link
http://www.postgresql.org/about/news.905 Broken Link
http://www.redhat.com/support/errata/RHSA-2008-0038.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2008-0039.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2008-0040.html Third Party Advisory
http://www.securityfocus.com/archive/1/485864/100/0/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/archive/1/486407/100/0/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/27163 Patch Third Party Advisory VDB Entry
http://www.vupen.com/english/advisories/2008/0061 Permissions Required
http://www.vupen.com/english/advisories/2008/0109 Permissions Required Third Party Advisory
http://www.vupen.com/english/advisories/2008/1071/references Permissions Required
https://exchange.xforce.ibmcloud.com/vulnerabilities/39500 Third Party Advisory VDB Entry
https://issues.rpath.com/browse/RPL-1768 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11127 Broken Link
https://usn.ubuntu.com/568-1/ Broken Link
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00397.html Mailing List Third Party Advisory
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00469.html Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:8.2:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:fedoraproject:fedora:7:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:*

History

21 Nov 2024, 00:40

Type Values Removed Values Added
References () http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154 - Broken Link () http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154 - Broken Link
References () http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00000.html - Broken Link () http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00000.html - Broken Link
References () http://secunia.com/advisories/28359 - Not Applicable, Vendor Advisory () http://secunia.com/advisories/28359 - Not Applicable, Vendor Advisory
References () http://secunia.com/advisories/28376 - Not Applicable () http://secunia.com/advisories/28376 - Not Applicable
References () http://secunia.com/advisories/28437 - Not Applicable () http://secunia.com/advisories/28437 - Not Applicable
References () http://secunia.com/advisories/28438 - Not Applicable () http://secunia.com/advisories/28438 - Not Applicable
References () http://secunia.com/advisories/28445 - Not Applicable () http://secunia.com/advisories/28445 - Not Applicable
References () http://secunia.com/advisories/28454 - Not Applicable () http://secunia.com/advisories/28454 - Not Applicable
References () http://secunia.com/advisories/28455 - Not Applicable () http://secunia.com/advisories/28455 - Not Applicable
References () http://secunia.com/advisories/28464 - Not Applicable () http://secunia.com/advisories/28464 - Not Applicable
References () http://secunia.com/advisories/28477 - Not Applicable () http://secunia.com/advisories/28477 - Not Applicable
References () http://secunia.com/advisories/28479 - Not Applicable () http://secunia.com/advisories/28479 - Not Applicable
References () http://secunia.com/advisories/28679 - Not Applicable () http://secunia.com/advisories/28679 - Not Applicable
References () http://secunia.com/advisories/28698 - Not Applicable () http://secunia.com/advisories/28698 - Not Applicable
References () http://secunia.com/advisories/29638 - Not Applicable () http://secunia.com/advisories/29638 - Not Applicable
References () http://security.gentoo.org/glsa/glsa-200801-15.xml - Third Party Advisory () http://security.gentoo.org/glsa/glsa-200801-15.xml - Third Party Advisory
References () http://securitytracker.com/id?1019157 - Broken Link, Third Party Advisory, VDB Entry () http://securitytracker.com/id?1019157 - Broken Link, Third Party Advisory, VDB Entry
References () http://sunsolve.sun.com/search/document.do?assetkey=1-26-103197-1 - Broken Link () http://sunsolve.sun.com/search/document.do?assetkey=1-26-103197-1 - Broken Link
References () http://sunsolve.sun.com/search/document.do?assetkey=1-66-200559-1 - Broken Link () http://sunsolve.sun.com/search/document.do?assetkey=1-66-200559-1 - Broken Link
References () http://www.debian.org/security/2008/dsa-1460 - Third Party Advisory () http://www.debian.org/security/2008/dsa-1460 - Third Party Advisory
References () http://www.debian.org/security/2008/dsa-1463 - Third Party Advisory () http://www.debian.org/security/2008/dsa-1463 - Third Party Advisory
References () http://www.mandriva.com/security/advisories?name=MDVSA-2008:004 - Broken Link () http://www.mandriva.com/security/advisories?name=MDVSA-2008:004 - Broken Link
References () http://www.postgresql.org/about/news.905 - Broken Link () http://www.postgresql.org/about/news.905 - Broken Link
References () http://www.redhat.com/support/errata/RHSA-2008-0038.html - Third Party Advisory () http://www.redhat.com/support/errata/RHSA-2008-0038.html - Third Party Advisory
References () http://www.redhat.com/support/errata/RHSA-2008-0039.html - Third Party Advisory () http://www.redhat.com/support/errata/RHSA-2008-0039.html - Third Party Advisory
References () http://www.redhat.com/support/errata/RHSA-2008-0040.html - Third Party Advisory () http://www.redhat.com/support/errata/RHSA-2008-0040.html - Third Party Advisory
References () http://www.securityfocus.com/archive/1/485864/100/0/threaded - Third Party Advisory, VDB Entry () http://www.securityfocus.com/archive/1/485864/100/0/threaded - Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/archive/1/486407/100/0/threaded - Third Party Advisory, VDB Entry () http://www.securityfocus.com/archive/1/486407/100/0/threaded - Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/27163 - Patch, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/27163 - Patch, Third Party Advisory, VDB Entry
References () http://www.vupen.com/english/advisories/2008/0061 - Permissions Required () http://www.vupen.com/english/advisories/2008/0061 - Permissions Required
References () http://www.vupen.com/english/advisories/2008/0109 - Permissions Required, Third Party Advisory () http://www.vupen.com/english/advisories/2008/0109 - Permissions Required, Third Party Advisory
References () http://www.vupen.com/english/advisories/2008/1071/references - Permissions Required () http://www.vupen.com/english/advisories/2008/1071/references - Permissions Required
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/39500 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/39500 - Third Party Advisory, VDB Entry
References () https://issues.rpath.com/browse/RPL-1768 - Broken Link () https://issues.rpath.com/browse/RPL-1768 - Broken Link
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11127 - Broken Link () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11127 - Broken Link
References () https://usn.ubuntu.com/568-1/ - Broken Link () https://usn.ubuntu.com/568-1/ - Broken Link
References () https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00397.html - Mailing List, Third Party Advisory () https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00397.html - Mailing List, Third Party Advisory
References () https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00469.html - Mailing List, Third Party Advisory () https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00469.html - Mailing List, Third Party Advisory

Information

Published : 2008-01-09 21:46

Updated : 2024-11-21 00:40


NVD link : CVE-2007-6601

Mitre link : CVE-2007-6601

CVE.ORG link : CVE-2007-6601


JSON object : View

Products Affected

debian

  • debian_linux

fedoraproject

  • fedora

postgresql

  • postgresql
CWE
CWE-287

Improper Authentication