CVE-2007-0555
Last modified
CVE-2007-0555 is a vulnerability of currently unknown severity. PostgreSQL 7.3 before 7.3.13, 7.4 before 7.4.16, 8.0 before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 allows attackers to disable certain checks for the data types of SQL function arguments, which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content.. EPSS estimates a 4.69% chance of exploitation in the next 30 days.
Description
PostgreSQL 7.3 before 7.3.13, 7.4 before 7.4.16, 8.0 before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 allows attackers to disable certain checks for the data types of SQL function arguments, which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Postgresql | Postgresql | >= 7.3, < 7.3.18 |
| Postgresql | Postgresql | >= 7.4, < 7.4.16 |
| Postgresql | Postgresql | >= 8.0, < 8.0.11 |
| Postgresql | Postgresql | >= 8.1, < 8.1.7 |
| Postgresql | Postgresql | >= 8.2, < 8.2.2 |
References
- ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.ascThird Party Advisory
- http://fedoranews.org/cms/node/2554Third Party Advisory
- http://osvdb.org/33087Broken Link
- http://secunia.com/advisories/24028Broken Link
- http://secunia.com/advisories/24033Broken Link
- http://secunia.com/advisories/24042Broken Link
- http://secunia.com/advisories/24050Broken Link
- http://secunia.com/advisories/24057Broken Link
- http://secunia.com/advisories/24094Broken Link
- http://secunia.com/advisories/24151Broken Link
- http://secunia.com/advisories/24158Broken Link
- http://secunia.com/advisories/24284Broken Link
- http://secunia.com/advisories/24315Broken Link
- http://secunia.com/advisories/24513Broken Link
- http://secunia.com/advisories/24577Broken Link
- http://secunia.com/advisories/25220Broken Link
- http://security.gentoo.org/glsa/glsa-200703-15.xmlThird Party Advisory
- http://securitytracker.com/id?1017597Third Party Advisory, VDB Entry
- http://support.avaya.com/elmodocs2/security/ASA-2007-117.htmThird Party Advisory
- http://www.debian.org/security/2007/dsa-1261Third Party Advisory
- http://www.novell.com/linux/security/advisories/2007_10_sr.htmlThird Party Advisory
- http://www.postgresql.org/support/securityVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0064.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0067.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0068.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/459280/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/459448/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/22387Third Party Advisory, VDB Entry
- http://www.trustix.org/errata/2007/0007Broken Link
- http://www.ubuntu.com/usn/usn-417-2Third Party Advisory
- http://www.vupen.com/english/advisories/2007/0478Third Party Advisory
- http://www.vupen.com/english/advisories/2007/0774Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32195Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-1025Broken Link
- https://issues.rpath.com/browse/RPL-830Broken Link
- https://usn.ubuntu.com/417-1/Third Party Advisory
- ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.ascThird Party Advisory
- http://fedoranews.org/cms/node/2554Third Party Advisory
- http://osvdb.org/33087Broken Link
- http://secunia.com/advisories/24028Broken Link
- http://secunia.com/advisories/24033Broken Link
- http://secunia.com/advisories/24042Broken Link
- http://secunia.com/advisories/24050Broken Link
- http://secunia.com/advisories/24057Broken Link
- http://secunia.com/advisories/24094Broken Link
- http://secunia.com/advisories/24151Broken Link
- http://secunia.com/advisories/24158Broken Link
- http://secunia.com/advisories/24284Broken Link
- http://secunia.com/advisories/24315Broken Link
- http://secunia.com/advisories/24513Broken Link
- http://secunia.com/advisories/24577Broken Link
- http://secunia.com/advisories/25220Broken Link
- http://security.gentoo.org/glsa/glsa-200703-15.xmlThird Party Advisory
- http://securitytracker.com/id?1017597Third Party Advisory, VDB Entry
- http://support.avaya.com/elmodocs2/security/ASA-2007-117.htmThird Party Advisory
- http://www.debian.org/security/2007/dsa-1261Third Party Advisory
- http://www.novell.com/linux/security/advisories/2007_10_sr.htmlThird Party Advisory
- http://www.postgresql.org/support/securityVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0064.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0067.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0068.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/459280/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/459448/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/22387Third Party Advisory, VDB Entry
- http://www.trustix.org/errata/2007/0007Broken Link
- http://www.ubuntu.com/usn/usn-417-2Third Party Advisory
- http://www.vupen.com/english/advisories/2007/0478Third Party Advisory
- http://www.vupen.com/english/advisories/2007/0774Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32195Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-1025Broken Link
- https://issues.rpath.com/browse/RPL-830Broken Link
- https://usn.ubuntu.com/417-1/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-0555?
How severe is CVE-2007-0555?
How do I fix CVE-2007-0555?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-0549Cross-site scripting (XSS) vulnerability in list3.php in 212…
- CVE-2007-0550Cross-site scripting (XSS) vulnerability in search.php in 21…
- CVE-2007-0551Multiple PHP remote file inclusion vulnerabilities in cmsimp…
- CVE-2007-0552Cross-site scripting (XSS) vulnerability in install/default/…
- CVE-2007-0553Multiple cross-site scripting (XSS) vulnerabilities in index…
- CVE-2007-0554SQL injection vulnerability in print.asp in Guo Xu Guos Post…
- CVE-2007-0556The query planner in PostgreSQL before 8.0.11, 8.1 before 8.…
- CVE-2007-0557rMake before 1.0.4 drops root privileges in a way that retai…
- CVE-2007-0558PHP remote file inclusion vulnerability in modules/mail/main…
- CVE-2007-0559PHP remote file inclusion vulnerability in config.php in RPW…
- CVE-2007-0560SQL injection vulnerability in user.asp in ASP EDGE 1.2b and…
- CVE-2007-0561Multiple PHP remote file inclusion vulnerabilities in Xero P…
Are you affected by CVE-2007-0555?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
