Логотип exploitDog
bind:"BDU:2019-04174" OR bind:"CVE-2017-7485"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2019-04174" OR bind:"CVE-2017-7485"

Количество 11

Количество 11

fstec логотип

BDU:2019-04174

около 8 лет назад

Уязвимость библиотеки libpq системы управления базами данных PostgreSQL, позволяющая нарушителю реализовать атаку типа «человек посередине»

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2017-7485

около 8 лет назад

In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-in-the-Middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2017-7485

около 8 лет назад

In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-in-the-Middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2017-7485

около 8 лет назад

In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-in-the-Middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2017-7485

около 8 лет назад

In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9 ...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-742m-4pjq-x8qf

около 3 лет назад

In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-in-the-Middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server.

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2017:1772-1

почти 8 лет назад

Security update for postgresql94

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2017:1495-1

около 8 лет назад

Security update for postgresql93

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1783-1

почти 8 лет назад

Security update for postgresql94

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1690-1

почти 8 лет назад

Security update for postgresql94

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1441-1

около 8 лет назад

Security update for postgresql93

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2019-04174

Уязвимость библиотеки libpq системы управления базами данных PostgreSQL, позволяющая нарушителю реализовать атаку типа «человек посередине»

CVSS3: 5.9
1%
Низкий
около 8 лет назад
ubuntu логотип
CVE-2017-7485

In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-in-the-Middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server.

CVSS3: 5.9
1%
Низкий
около 8 лет назад
redhat логотип
CVE-2017-7485

In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-in-the-Middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server.

CVSS3: 7.4
1%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-7485

In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-in-the-Middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server.

CVSS3: 5.9
1%
Низкий
около 8 лет назад
debian логотип
CVE-2017-7485

In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9 ...

CVSS3: 5.9
1%
Низкий
около 8 лет назад
github логотип
GHSA-742m-4pjq-x8qf

In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-in-the-Middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server.

CVSS3: 5.9
1%
Низкий
около 3 лет назад
suse-cvrf логотип
openSUSE-SU-2017:1772-1

Security update for postgresql94

почти 8 лет назад
suse-cvrf логотип
openSUSE-SU-2017:1495-1

Security update for postgresql93

около 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:1783-1

Security update for postgresql94

почти 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:1690-1

Security update for postgresql94

почти 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:1441-1

Security update for postgresql93

около 8 лет назад

Уязвимостей на страницу