PT-2007-4557 · Postgresql+1 · Postgresql+1
Published
2007-06-19
·
Updated
2023-02-24
·
CVE-2007-3278
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PostgreSQL versions 8.1 and later
Description
The issue allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries. This is possible when local trust authentication is enabled and the Database Link library (dblink) is installed. Attackers can exploit this by using a dblink host parameter that proxies the connection from 127.0.0.1.
Recommendations
For PostgreSQL versions 8.1 and later, consider disabling the Database Link library (dblink) or restricting its use to prevent exploitation. Additionally, review and restrict local trust authentication settings to minimize the risk of unauthorized access.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Postgresql
Red Hat