CVE-2007-6601
Last modified
CVE-2007-6601 is a vulnerability of currently unknown severity. The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2007-3278.. EPSS estimates a 1.57% chance of exploitation in the next 30 days.
Description
The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2007-3278.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Postgresql | Postgresql | >= 7.3.0, < 7.3.21 |
| Postgresql | Postgresql | >= 7.4.0, < 7.4.19 |
| Postgresql | Postgresql | >= 8.0.0, < 8.0.15 |
| Postgresql | Postgresql | >= 8.1.0, < 8.1.11 |
| Postgresql | Postgresql | >= 8.2.0, < 8.2.6 |
| Postgresql | Postgresql | 8.2 |
| Debian | Debian Linux | 3.1 |
| Debian | Debian Linux | 4.0 |
| Fedoraproject | Fedora | 7 |
| Fedoraproject | Fedora | 8 |
References
- http://secunia.com/advisories/28359Not Applicable, Vendor Advisory
- http://secunia.com/advisories/28376Not Applicable
- http://secunia.com/advisories/28437Not Applicable
- http://secunia.com/advisories/28438Not Applicable
- http://secunia.com/advisories/28445Not Applicable
- http://secunia.com/advisories/28454Not Applicable
- http://secunia.com/advisories/28455Not Applicable
- http://secunia.com/advisories/28464Not Applicable
- http://secunia.com/advisories/28477Not Applicable
- http://secunia.com/advisories/28479Not Applicable
- http://secunia.com/advisories/28679Not Applicable
- http://secunia.com/advisories/28698Not Applicable
- http://secunia.com/advisories/29638Not Applicable
- http://security.gentoo.org/glsa/glsa-200801-15.xmlThird Party Advisory
- http://securitytracker.com/id?1019157Broken Link, Third Party Advisory, VDB Entry
- http://www.debian.org/security/2008/dsa-1460Third Party Advisory
- http://www.debian.org/security/2008/dsa-1463Third Party Advisory
- http://www.postgresql.org/about/news.905Broken Link
- http://www.redhat.com/support/errata/RHSA-2008-0038.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0039.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0040.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/485864/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/486407/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/27163Patch, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/0061Permissions Required
- http://www.vupen.com/english/advisories/2008/0109Permissions Required, Third Party Advisory
- http://www.vupen.com/english/advisories/2008/1071/referencesPermissions Required
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39500Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-1768Broken Link
- https://usn.ubuntu.com/568-1/Broken Link
- https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00397.htmlMailing List, Third Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00469.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/28359Not Applicable, Vendor Advisory
- http://secunia.com/advisories/28376Not Applicable
- http://secunia.com/advisories/28437Not Applicable
- http://secunia.com/advisories/28438Not Applicable
- http://secunia.com/advisories/28445Not Applicable
- http://secunia.com/advisories/28454Not Applicable
- http://secunia.com/advisories/28455Not Applicable
- http://secunia.com/advisories/28464Not Applicable
- http://secunia.com/advisories/28477Not Applicable
- http://secunia.com/advisories/28479Not Applicable
- http://secunia.com/advisories/28679Not Applicable
- http://secunia.com/advisories/28698Not Applicable
- http://secunia.com/advisories/29638Not Applicable
- http://security.gentoo.org/glsa/glsa-200801-15.xmlThird Party Advisory
- http://securitytracker.com/id?1019157Broken Link, Third Party Advisory, VDB Entry
- http://www.debian.org/security/2008/dsa-1460Third Party Advisory
- http://www.debian.org/security/2008/dsa-1463Third Party Advisory
- http://www.postgresql.org/about/news.905Broken Link
- http://www.redhat.com/support/errata/RHSA-2008-0038.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0039.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0040.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/485864/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/486407/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/27163Patch, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/0061Permissions Required
- http://www.vupen.com/english/advisories/2008/0109Permissions Required, Third Party Advisory
- http://www.vupen.com/english/advisories/2008/1071/referencesPermissions Required
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39500Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-1768Broken Link
- https://usn.ubuntu.com/568-1/Broken Link
- https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00397.htmlMailing List, Third Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00469.htmlMailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-6601?
How severe is CVE-2007-6601?
How do I fix CVE-2007-6601?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-6595ClamAV 0.92 allows local users to overwrite arbitrary files …
- CVE-2007-6596ClamAV 0.92 does not recognize Base64 UUEncoded archives, wh…
- CVE-2007-6597Multiple cross-site scripting (XSS) vulnerabilities in IPort…
- CVE-2007-6598Dovecot before 1.0.10, with certain configuration options in…
- CVE-2007-6599Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5…
- CVE-2007-6600PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8…
- CVE-2007-6602SQL injection vulnerability in app/models/identity.php in No…
- CVE-2007-6603Hot or Not Clone has insufficient access control for produci…
- CVE-2007-6604Multiple directory traversal vulnerabilities in index.php in…
- CVE-2007-6605Buffer overflow in a certain ActiveX control in SkyFexClient…
- CVE-2007-6606OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to…
- CVE-2007-6607OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to…
Are you affected by CVE-2007-6601?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
