CVE-2007-3278

PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1.
References
Link Resource
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154 Third Party Advisory
http://osvdb.org/40899 Broken Link
http://secunia.com/advisories/28376 Broken Link
http://secunia.com/advisories/28437 Broken Link
http://secunia.com/advisories/28438 Broken Link
http://secunia.com/advisories/28445 Broken Link
http://secunia.com/advisories/28454 Broken Link
http://secunia.com/advisories/28477 Broken Link
http://secunia.com/advisories/28479 Broken Link
http://secunia.com/advisories/28679 Broken Link
http://secunia.com/advisories/29638 Broken Link
http://security.gentoo.org/glsa/glsa-200801-15.xml Third Party Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103197-1 Broken Link
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200559-1 Broken Link
http://www.debian.org/security/2008/dsa-1460 Third Party Advisory
http://www.debian.org/security/2008/dsa-1463 Third Party Advisory
http://www.leidecker.info/pgshell/Having_Fun_With_PostgreSQL.txt Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2007:188 Third Party Advisory
http://www.portcullis.co.uk/uplds/whitepapers/Having_Fun_With_PostgreSQL.pdf Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2008-0038.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2008-0039.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2008-0040.html Third Party Advisory
http://www.securityfocus.com/archive/1/471541/100/0/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/archive/1/471644/100/0/threaded Third Party Advisory VDB Entry
http://www.vupen.com/english/advisories/2008/0109 Permissions Required
http://www.vupen.com/english/advisories/2008/1071/references Permissions Required
https://exchange.xforce.ibmcloud.com/vulnerabilities/35142 Third Party Advisory VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10334 Third Party Advisory
https://usn.ubuntu.com/568-1/ Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*

History

24 Feb 2023, 15:35

Type Values Removed Values Added
References (REDHAT) http://www.redhat.com/support/errata/RHSA-2008-0039.html - (REDHAT) http://www.redhat.com/support/errata/RHSA-2008-0039.html - Third Party Advisory
References (GENTOO) http://security.gentoo.org/glsa/glsa-200801-15.xml - (GENTOO) http://security.gentoo.org/glsa/glsa-200801-15.xml - Third Party Advisory
References (DEBIAN) http://www.debian.org/security/2008/dsa-1463 - (DEBIAN) http://www.debian.org/security/2008/dsa-1463 - Third Party Advisory
References (SECUNIA) http://secunia.com/advisories/28454 - Vendor Advisory (SECUNIA) http://secunia.com/advisories/28454 - Broken Link
References (MANDRIVA) http://www.mandriva.com/security/advisories?name=MDKSA-2007:188 - (MANDRIVA) http://www.mandriva.com/security/advisories?name=MDKSA-2007:188 - Third Party Advisory
References (SECUNIA) http://secunia.com/advisories/28445 - Vendor Advisory (SECUNIA) http://secunia.com/advisories/28445 - Broken Link
References (BUGTRAQ) http://www.securityfocus.com/archive/1/471644/100/0/threaded - (BUGTRAQ) http://www.securityfocus.com/archive/1/471644/100/0/threaded - Third Party Advisory, VDB Entry
References (SECUNIA) http://secunia.com/advisories/28438 - Vendor Advisory (SECUNIA) http://secunia.com/advisories/28438 - Broken Link
References (VUPEN) http://www.vupen.com/english/advisories/2008/1071/references - (VUPEN) http://www.vupen.com/english/advisories/2008/1071/references - Permissions Required
References (HP) http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154 - (HP) http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154 - Third Party Advisory
References (REDHAT) http://www.redhat.com/support/errata/RHSA-2008-0040.html - (REDHAT) http://www.redhat.com/support/errata/RHSA-2008-0040.html - Third Party Advisory
References (SECUNIA) http://secunia.com/advisories/28679 - Vendor Advisory (SECUNIA) http://secunia.com/advisories/28679 - Broken Link
References (SECUNIA) http://secunia.com/advisories/29638 - (SECUNIA) http://secunia.com/advisories/29638 - Broken Link
References (BUGTRAQ) http://www.securityfocus.com/archive/1/471541/100/0/threaded - (BUGTRAQ) http://www.securityfocus.com/archive/1/471541/100/0/threaded - Third Party Advisory, VDB Entry
References (DEBIAN) http://www.debian.org/security/2008/dsa-1460 - (DEBIAN) http://www.debian.org/security/2008/dsa-1460 - Third Party Advisory
References (SUNALERT) http://sunsolve.sun.com/search/document.do?assetkey=1-26-103197-1 - (SUNALERT) http://sunsolve.sun.com/search/document.do?assetkey=1-26-103197-1 - Broken Link
References (MISC) http://www.leidecker.info/pgshell/Having_Fun_With_PostgreSQL.txt - (MISC) http://www.leidecker.info/pgshell/Having_Fun_With_PostgreSQL.txt - Third Party Advisory
References (OSVDB) http://osvdb.org/40899 - (OSVDB) http://osvdb.org/40899 - Broken Link
References (REDHAT) http://www.redhat.com/support/errata/RHSA-2008-0038.html - (REDHAT) http://www.redhat.com/support/errata/RHSA-2008-0038.html - Third Party Advisory
References (VUPEN) http://www.vupen.com/english/advisories/2008/0109 - (VUPEN) http://www.vupen.com/english/advisories/2008/0109 - Permissions Required
References (OVAL) https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10334 - (OVAL) https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10334 - Third Party Advisory
References (UBUNTU) https://usn.ubuntu.com/568-1/ - (UBUNTU) https://usn.ubuntu.com/568-1/ - Third Party Advisory
References (MISC) http://www.portcullis.co.uk/uplds/whitepapers/Having_Fun_With_PostgreSQL.pdf - (MISC) http://www.portcullis.co.uk/uplds/whitepapers/Having_Fun_With_PostgreSQL.pdf - Third Party Advisory
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/35142 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/35142 - Third Party Advisory, VDB Entry
References (SECUNIA) http://secunia.com/advisories/28477 - Vendor Advisory (SECUNIA) http://secunia.com/advisories/28477 - Broken Link
References (SUNALERT) http://sunsolve.sun.com/search/document.do?assetkey=1-66-200559-1 - (SUNALERT) http://sunsolve.sun.com/search/document.do?assetkey=1-66-200559-1 - Broken Link
References (SECUNIA) http://secunia.com/advisories/28376 - Vendor Advisory (SECUNIA) http://secunia.com/advisories/28376 - Broken Link
References (SECUNIA) http://secunia.com/advisories/28479 - Vendor Advisory (SECUNIA) http://secunia.com/advisories/28479 - Broken Link
References (SECUNIA) http://secunia.com/advisories/28437 - Vendor Advisory (SECUNIA) http://secunia.com/advisories/28437 - Broken Link
First Time Debian
Debian debian Linux
CPE cpe:2.3:a:postgresql:postgresql:8.1:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*

Information

Published : 2007-06-19 21:30

Updated : 2023-12-10 10:40


NVD link : CVE-2007-3278

Mitre link : CVE-2007-3278

CVE.ORG link : CVE-2007-3278


JSON object : View

Products Affected

postgresql

  • postgresql

debian

  • debian_linux
CWE
CWE-264

Permissions, Privileges, and Access Controls