CVE-2007-6601
published 2008-01-09CVE-2007-6601: The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident…
PriorityP433high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
1.57%
72.7th percentile
The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2007-3278.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | >= 7.3.0 < 7.3.21 | 7.3.21 |
| postgresql | postgresql | >= 7.4.0 < 7.4.19 | 7.4.19 |
| postgresql | postgresql | >= 8.0.0 < 8.0.15 | 8.0.15 |
| postgresql | postgresql | >= 8.1.0 < 8.1.11 | 8.1.11 |
| postgresql | postgresql | >= 8.2.0 < 8.2.6 | 8.2.6 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat6.9MEDIUM
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2008-01-14·CVSS 6.9
CVE-2007-3278 [MEDIUM] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: PostgreSQL vulnerabilities
Nico Leidecker discovered that PostgreSQL did not properly
restrict dblink functions. An authenticated user could exploit
this flaw to access arbitrary accounts and execute arbitrary
SQL queries. (CVE-2007-3278, CVE-2007-6601)
It was discovered that the TCL regular expression parser used
by PostgreSQL did not properly check its input. An attacker
could send crafted regular expressions to PostgreSQL and cause
a denial of service via resource exhaustion or database crash.
(CVE-2007-4769, CVE-2007-4772, CVE-2007-6067)
It was discovered that PostgreSQL executed VACUUM and ANALYZE
operations within index functions with superuser privileges and
also allowed SET ROLE and SET SESSION AUTHORIZATION within index
functions. A r
Red Hat
PostgreSQL privilege escalation via dblink
vendor_redhat·2008-01-07·CVSS 6.9
CVE-2007-6601 [MEDIUM] PostgreSQL privilege escalation via dblink
PostgreSQL privilege escalation via dblink
The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2007-3278.
GHSA
GHSA-98mv-g9r2-mwm3: The DBLink module in PostgreSQL 8
ghsa_unreviewed·2022-05-01·CVSS 6.9
CVE-2007-6601 [MEDIUM] CWE-287 GHSA-98mv-g9r2-mwm3: The DBLink module in PostgreSQL 8
The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2007-3278.
No detection rules found.
No public exploits indexed.
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00000.htmlhttp://secunia.com/advisories/28359http://secunia.com/advisories/28376http://secunia.com/advisories/28437http://secunia.com/advisories/28438http://secunia.com/advisories/28445http://secunia.com/advisories/28454http://secunia.com/advisories/28455http://secunia.com/advisories/28464http://secunia.com/advisories/28477http://secunia.com/advisories/28479http://secunia.com/advisories/28679http://secunia.com/advisories/28698http://secunia.com/advisories/29638http://security.gentoo.org/glsa/glsa-200801-15.xmlhttp://securitytracker.com/id?1019157http://sunsolve.sun.com/search/document.do?assetkey=1-26-103197-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-200559-1http://www.debian.org/security/2008/dsa-1460http://www.debian.org/security/2008/dsa-1463http://www.mandriva.com/security/advisories?name=MDVSA-2008:004http://www.postgresql.org/about/news.905http://www.redhat.com/support/errata/RHSA-2008-0038.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0039.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0040.htmlhttp://www.securityfocus.com/archive/1/485864/100/0/threadedhttp://www.securityfocus.com/archive/1/486407/100/0/threadedhttp://www.securityfocus.com/bid/27163http://www.vupen.com/english/advisories/2008/0061http://www.vupen.com/english/advisories/2008/0109http://www.vupen.com/english/advisories/2008/1071/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/39500https://issues.rpath.com/browse/RPL-1768https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11127https://usn.ubuntu.com/568-1/https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00397.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-January/msg00469.htmlhttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00000.htmlhttp://secunia.com/advisories/28359http://secunia.com/advisories/28376http://secunia.com/advisories/28437http://secunia.com/advisories/28438http://secunia.com/advisories/28445http://secunia.com/advisories/28454http://secunia.com/advisories/28455http://secunia.com/advisories/28464http://secunia.com/advisories/28477http://secunia.com/advisories/28479http://secunia.com/advisories/28679http://secunia.com/advisories/28698http://secunia.com/advisories/29638http://security.gentoo.org/glsa/glsa-200801-15.xmlhttp://securitytracker.com/id?1019157http://sunsolve.sun.com/search/document.do?assetkey=1-26-103197-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-200559-1http://www.debian.org/security/2008/dsa-1460http://www.debian.org/security/2008/dsa-1463http://www.mandriva.com/security/advisories?name=MDVSA-2008:004http://www.postgresql.org/about/news.905http://www.redhat.com/support/errata/RHSA-2008-0038.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0039.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0040.htmlhttp://www.securityfocus.com/archive/1/485864/100/0/threadedhttp://www.securityfocus.com/archive/1/486407/100/0/threadedhttp://www.securityfocus.com/bid/27163http://www.vupen.com/english/advisories/2008/0061http://www.vupen.com/english/advisories/2008/0109http://www.vupen.com/english/advisories/2008/1071/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/39500https://issues.rpath.com/browse/RPL-1768https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11127https://usn.ubuntu.com/568-1/https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00397.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-January/msg00469.html
2008-01-09
Published