Vulnerability Name: | CVE-2007-3278 (CCN-35142) |
Assigned: | 2007-06-16 |
Published: | 2007-06-16 |
Updated: | 2023-02-24 |
Summary: | PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1. |
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): High Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): Low Availibility (A): Low |
|
CVSS v2 Severity: | 6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C) 5.1 Medium (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Local Access Complexity (AC): Medium Authentication (Au): None | Impact Metrics: | Confidentiality (C): Complete Integrity (I): Complete Availibility (A): Complete | 5.1 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P) 3.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): High Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Partial |
|
Vulnerability Consequences: | Data Manipulation |
References: | Source: CCN Type: BugTraq Mailing List, Sat Jun 16 2007 - 12:11:47 CDT Having Fun With PostgreSQL
Source: CCN Type: BugTraq Mailing List, Mon Jun 18 2007 - 07:56:56 CDT Re: Having Fun With PostgreSQL
Source: MITRE Type: CNA CVE-2007-3278
Source: CCN Type: HP Security Bulletin HPSBTU02325 SSRT080006 rev.1 HP Internet Express for Tru64 UNIX running PostgreSQL, Arbitrary Code Execution, Privilege Elevation, or Denial of Service (DoS)
Source: cve@mitre.org Type: Third Party Advisory cve@mitre.org
Source: CCN Type: RHSA-2008-0038 Moderate: postgresql security update
Source: CCN Type: RHSA-2008-0039 Moderate: postgresql security update
Source: CCN Type: RHSA-2008-0040 Moderate: postgresql security update
Source: CCN Type: SA28437 Sun Solaris 10 PostgreSQL Multiple Vulnerabilities
Source: CCN Type: SA29638 HP Internet Express for Tru64 UNIX Multiple PostgreSQL Vulnerabilities
Source: cve@mitre.org Type: Third Party Advisory cve@mitre.org
Source: CCN Type: Sun Alert ID: 103197 Multiple Security Vulnerabilities in PostgreSQL Shipped with Solaris 10 May Allow Elevation of Privileges or Denial of Service (DoS)
Source: cve@mitre.org Type: Broken Link cve@mitre.org
Source: cve@mitre.org Type: Broken Link cve@mitre.org
Source: CCN Type: ASA-2008-025 PostgreSQL security update (RHSA-2008-0039)
Source: CCN Type: ASA-2008-033 PostgreSQL security update (RHSA-2008-0038)
Source: CCN Type: ASA-2008-046 Multiple Security Vulnerabilities in PostgreSQL Shipped with Solaris 10 May Allow Elevation of Privileges or Denial of Service (DoS) (Sun 103197)
Source: CCN Type: ASA-2008-052 postgresql security update (RHSA-2008-0040)
Source: CCN Type: ASA-2008-074 Multiple Security Vulnerabilities in PostgreSQL Shipped with Solaris 10 May Allow Elevation of Privileges or Denial of Service (DoS) (Sun 200559)
Source: cve@mitre.org Type: Third Party Advisory cve@mitre.org
Source: cve@mitre.org Type: Third Party Advisory cve@mitre.org
Source: DEBIAN Type: DSA-1460 postgresql-8.1 -- several vulnerabilities
Source: DEBIAN Type: DSA-1463 postgresql-7.4 -- several vulnerabilities
Source: CCN Type: GLSA-200801-15 PostgreSQL: Multiple vulnerabilities
Source: cve@mitre.org Type: Third Party Advisory cve@mitre.org
Source: cve@mitre.org Type: Third Party Advisory cve@mitre.org
Source: CCN Type: OSVDB ID: 40899 PostgreSQL dblink host Variable Crafted Localhost Proxy Remote Privilege Escalation
Source: cve@mitre.org Type: Third Party Advisory cve@mitre.org
Source: CCN Type: PostgreSQL Web site PostgreSQL: The world's most advanced open source database
Source: cve@mitre.org Type: Third Party Advisory cve@mitre.org
Source: cve@mitre.org Type: Third Party Advisory cve@mitre.org
Source: cve@mitre.org Type: Third Party Advisory cve@mitre.org
Source: cve@mitre.org Type: Third Party Advisory, VDB Entry cve@mitre.org
Source: cve@mitre.org Type: Third Party Advisory, VDB Entry cve@mitre.org
Source: CCN Type: TLSA-2008-6 Three vulnerabilities discovered in postgresql
Source: CCN Type: USN-568-1 PostgreSQL vulnerabilities
Source: cve@mitre.org Type: Permissions Required cve@mitre.org
Source: cve@mitre.org Type: Permissions Required cve@mitre.org
Source: cve@mitre.org Type: Third Party Advisory, VDB Entry cve@mitre.org
Source: XF Type: UNKNOWN postgresql-dblink-sql-injection(35142)
Source: cve@mitre.org Type: Third Party Advisory cve@mitre.org
Source: cve@mitre.org Type: Third Party Advisory cve@mitre.org
|
Vulnerable Configuration: | Configuration RedHat 1: cpe:/o:redhat:enterprise_linux:4:*:*:*:*:*:*:*Configuration RedHat 2: cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*Configuration RedHat 3: cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*Configuration RedHat 4: cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*Configuration RedHat 5: cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*Configuration RedHat 6: cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*Configuration RedHat 7: cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:*Configuration RedHat 8: cpe:/o:redhat:enterprise_linux:5::client_workstation:*:*:*:*:*Configuration RedHat 9: cpe:/o:redhat:enterprise_linux:5::server:*:*:*:*:* Configuration CCN 1: cpe:/a:postgresql:postgresql:8.1:*:*:*:*:*:*:*AND cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux:3::ws:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux:3::es:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux:3::as:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux:3::desktop:*:*:*:*:*OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0:*:*:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*OR cpe:/o:debian:debian_linux:3.1:*:*:*:*:*:*:*OR cpe:/o:sun:solaris:10::sparc:*:*:*:*:*OR cpe:/o:sun:solaris:10::x86:*:*:*:*:*OR cpe:/o:canonical:ubuntu:6.06::lts:*:*:*:*:*OR cpe:/o:mandrakesoft:mandrake_linux:2007:*:*:*:*:*:*:*OR cpe:/o:mandrakesoft:mandrake_linux:2007::x86_64:*:*:*:*:*OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:*:*:*:*:*:*OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0::x86_64:*:*:*:*:*OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0::x86_64:*:*:*:*:*OR cpe:/o:turbolinux:turbolinux:fuji:*:*:*:*:*:*:*OR cpe:/o:turbolinux:turbolinux:*:*:personal:*:*:*:*:*OR cpe:/o:turbolinux:turbolinux:*:*:multimedia:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux:5:*:client_workstation:*:*:*:*:*OR cpe:/o:mandrakesoft:mandrake_linux:2007.1:*:*:*:*:*:*:*OR cpe:/o:mandrakesoft:mandrake_linux:2008.0::x86-64:*:*:*:*:*OR cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*OR cpe:/o:canonical:ubuntu:7.04:*:*:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux:5:*:client:*:*:*:*:*OR cpe:/o:canonical:ubuntu:7.10:*:*:*:*:*:*:*OR cpe:/o:mandrakesoft:mandrake_linux:2008.0:*:*:*:*:*:*:*OR cpe:/o:mandrakesoft:mandrake_linux:2007.1::x86-64:*:*:*:*:*OR cpe:/a:redhat:rhel_application_stack:2:*:*:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux:4.6.z:ga:as:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux:4.6.z:ga:es:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
|
BACK |
postgresql postgresql 8.1
gentoo linux *
redhat enterprise linux 3
redhat enterprise linux 3
redhat enterprise linux 3
redhat enterprise linux 3
mandrakesoft mandrake linux corporate server 3.0
redhat enterprise linux 4
redhat enterprise linux 4
redhat enterprise linux 4
redhat enterprise linux 4
debian debian linux 3.1
sun solaris 10
sun solaris 10
canonical ubuntu 6.06
mandrakesoft mandrake linux 2007
mandrakesoft mandrake linux 2007
mandrakesoft mandrake linux corporate server 4.0
mandrakesoft mandrake linux corporate server 4.0
mandrakesoft mandrake linux corporate server 3.0
turbolinux turbolinux fuji
turbolinux turbolinux personal *
turbolinux turbolinux multimedia *
redhat enterprise linux 5
redhat enterprise linux 5
mandrakesoft mandrake linux 2007.1
mandrakesoft mandrake linux 2008.0
debian debian linux 4.0
canonical ubuntu 7.04
redhat enterprise linux 5
canonical ubuntu 7.10
mandrakesoft mandrake linux 2008.0
mandrakesoft mandrake linux 2007.1
redhat rhel application stack 2
redhat enterprise linux 4.6.z ga
redhat enterprise linux 4.6.z ga