PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1.
CVSS Details
- CVSS 3.1 Base Score: 8.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-db/postgresql. | Oct 30, 2017 | Jun 19, 2007 |
| Oracle_linux | — | Upgrade postgresql-contribUpgrade postgresql-pythonUpgrade postgresql-tclUpgrade postgresql-plUpgrade postgresql-docsUpgrade postgresql-develUpgrade postgresqlUpgrade postgresql-serverUpgrade postgresql-libsUpgrade postgresql-test | Oct 16, 2024 | Jun 19, 2007 |
| Ubuntu | — | Upgrade postgresql-pltcl-8.2Upgrade postgresql-8.1Upgrade postgresql-8.2Upgrade postgresql-pltcl-8.1 | Nov 8, 2024 | Jun 19, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub