Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-3231

Опубликовано: 09 сент. 2009
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.

Отчет

Not vulnerable. This issue did not affect the versions of PostgreSQL as shipped with Red Hat Enterprise Linux 3, 4, or 5, as they do not support LDAP authentication, which was introduced upstream in version 8.2.

Ссылки на источники

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=522084postgresql: LDAP authentication bypass when anonymous LDAP bind are allowed

EPSS

Процентиль: 89%
0.04962
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 16 лет назад

The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.

nvd
почти 16 лет назад

The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.

debian
почти 16 лет назад

The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 befor ...

github
около 3 лет назад

The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.

EPSS

Процентиль: 89%
0.04962
Низкий

6.8 Medium

CVSS2