CVE-2007-3278
Last modified
CVE-2007-3278 is a vulnerability of currently unknown severity. PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1.. EPSS estimates a 1.26% chance of exploitation in the next 30 days.
Description
PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Postgresql | Postgresql | >= 7.3, < 7.3.21 |
| Postgresql | Postgresql | >= 7.4, < 7.4.19 |
| Postgresql | Postgresql | >= 8.0, < 8.0.15 |
| Postgresql | Postgresql | >= 8.1, < 8.1.11 |
| Postgresql | Postgresql | >= 8.2, < 8.2.6 |
| Debian | Debian Linux | 3.1 |
| Debian | Debian Linux | 4.0 |
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154Third Party Advisory
- http://osvdb.org/40899Broken Link
- http://secunia.com/advisories/28376Broken Link
- http://secunia.com/advisories/28437Broken Link
- http://secunia.com/advisories/28438Broken Link
- http://secunia.com/advisories/28445Broken Link
- http://secunia.com/advisories/28454Broken Link
- http://secunia.com/advisories/28477Broken Link
- http://secunia.com/advisories/28479Broken Link
- http://secunia.com/advisories/28679Broken Link
- http://secunia.com/advisories/29638Broken Link
- http://security.gentoo.org/glsa/glsa-200801-15.xmlThird Party Advisory
- http://www.debian.org/security/2008/dsa-1460Third Party Advisory
- http://www.debian.org/security/2008/dsa-1463Third Party Advisory
- http://www.leidecker.info/pgshell/Having_Fun_With_PostgreSQL.txtThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:188Third Party Advisory
- http://www.portcullis.co.uk/uplds/whitepapers/Having_Fun_With_PostgreSQL.pdfThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0038.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0039.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0040.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/471541/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/471644/100/0/threadedThird Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/0109Permissions Required
- http://www.vupen.com/english/advisories/2008/1071/referencesPermissions Required
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35142Third Party Advisory, VDB Entry
- https://usn.ubuntu.com/568-1/Third Party Advisory
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154Third Party Advisory
- http://osvdb.org/40899Broken Link
- http://secunia.com/advisories/28376Broken Link
- http://secunia.com/advisories/28437Broken Link
- http://secunia.com/advisories/28438Broken Link
- http://secunia.com/advisories/28445Broken Link
- http://secunia.com/advisories/28454Broken Link
- http://secunia.com/advisories/28477Broken Link
- http://secunia.com/advisories/28479Broken Link
- http://secunia.com/advisories/28679Broken Link
- http://secunia.com/advisories/29638Broken Link
- http://security.gentoo.org/glsa/glsa-200801-15.xmlThird Party Advisory
- http://www.debian.org/security/2008/dsa-1460Third Party Advisory
- http://www.debian.org/security/2008/dsa-1463Third Party Advisory
- http://www.leidecker.info/pgshell/Having_Fun_With_PostgreSQL.txtThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:188Third Party Advisory
- http://www.portcullis.co.uk/uplds/whitepapers/Having_Fun_With_PostgreSQL.pdfThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0038.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0039.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0040.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/471541/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/471644/100/0/threadedThird Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/0109Permissions Required
- http://www.vupen.com/english/advisories/2008/1071/referencesPermissions Required
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35142Third Party Advisory, VDB Entry
- https://usn.ubuntu.com/568-1/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-3278?
How severe is CVE-2007-3278?
How do I fix CVE-2007-3278?
Are you affected by CVE-2007-3278?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
