Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2007-3278

Опубликовано: 16 июн. 2007
Источник: redhat
EPSS Низкий

Описание

PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1.

Отчет

Red Hat does not consider this do be a security issue. dblink is disabled in default configuration of PostgreSQL packages as shipped with Red Hat Enterprise Linux versions 2.1, 3, 4 and 5, and it is a configuration decision whether to grant local users arbitrary access.

Дополнительная информация

https://bugzilla.redhat.com/show_bug.cgi?id=309141dblink allows proxying of database connections via 127.0.0.1

EPSS

Процентиль: 68%
0.00584
Низкий

Связанные уязвимости

ubuntu
около 18 лет назад

PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1.

nvd
около 18 лет назад

PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1.

debian
около 18 лет назад

PostgreSQL 8.1 and probably later versions, when local trust authentic ...

github
около 3 лет назад

PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1.

oracle-oval
больше 17 лет назад

ELSA-2008-0038: Moderate: postgresql security update (MODERATE)

EPSS

Процентиль: 68%
0.00584
Низкий