CVE-2007-6601

critical

Description

The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2007-3278.

References

https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00469.html

https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00397.html

https://exchange.xforce.ibmcloud.com/vulnerabilities/39500

http://www.vupen.com/english/advisories/2008/1071/references

http://www.vupen.com/english/advisories/2008/0109

http://www.vupen.com/english/advisories/2008/0061

http://www.securityfocus.com/bid/27163

http://www.securityfocus.com/archive/1/486407/100/0/threaded

http://www.securityfocus.com/archive/1/485864/100/0/threaded

http://www.redhat.com/support/errata/RHSA-2008-0040.html

http://www.redhat.com/support/errata/RHSA-2008-0039.html

http://www.redhat.com/support/errata/RHSA-2008-0038.html

http://www.debian.org/security/2008/dsa-1463

http://www.debian.org/security/2008/dsa-1460

http://security.gentoo.org/glsa/glsa-200801-15.xml

http://secunia.com/advisories/29638

http://secunia.com/advisories/28698

http://secunia.com/advisories/28679

http://secunia.com/advisories/28479

http://secunia.com/advisories/28477

http://secunia.com/advisories/28464

http://secunia.com/advisories/28455

http://secunia.com/advisories/28454

http://secunia.com/advisories/28445

http://secunia.com/advisories/28438

http://secunia.com/advisories/28437

http://secunia.com/advisories/28376

http://secunia.com/advisories/28359

Details

Source: Mitre, NVD

Published: 2008-01-09

Updated: 2023-01-18

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical