CVE Database
/

CVE-2007-3278

Back to search

CVE-2007-3278

Published: Jun 19, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1.

VendorProductVersions

n/a

n/a

affected
n/a

References

DSA-1460
vendor-advisory
x_refsource_DEBIAN
28445
third-party-advisory
x_refsource_SECUNIA
RHSA-2008:0038
vendor-advisory
x_refsource_REDHAT
20070618 Re: Having Fun With PostgreSQL
mailing-list
x_refsource_BUGTRAQ
28454
third-party-advisory
x_refsource_SECUNIA
28679
third-party-advisory
x_refsource_SECUNIA
ADV-2008-0109
vdb-entry
x_refsource_VUPEN
MDKSA-2007:188
vendor-advisory
x_refsource_MANDRIVA
28376
third-party-advisory
x_refsource_SECUNIA
103197
vendor-advisory
x_refsource_SUNALERT
28437
third-party-advisory
x_refsource_SECUNIA
28477
third-party-advisory
x_refsource_SECUNIA
29638
third-party-advisory
x_refsource_SECUNIA
28479
third-party-advisory
x_refsource_SECUNIA
DSA-1463
vendor-advisory
x_refsource_DEBIAN
RHSA-2008:0040
vendor-advisory
x_refsource_REDHAT
SSRT080006
vendor-advisory
x_refsource_HP
200559
vendor-advisory
x_refsource_SUNALERT
oval:org.mitre.oval:def:10334
vdb-entry
signature
x_refsource_OVAL
USN-568-1
vendor-advisory
x_refsource_UBUNTU
28438
third-party-advisory
x_refsource_SECUNIA
20070616 Having Fun With PostgreSQL
mailing-list
x_refsource_BUGTRAQ
RHSA-2008:0039
vendor-advisory
x_refsource_REDHAT
HPSBTU02325
vendor-advisory
x_refsource_HP
GLSA-200801-15
vendor-advisory
x_refsource_GENTOO
40899
vdb-entry
x_refsource_OSVDB
ADV-2008-1071
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now