cbcvebase.
CVE-2007-6601
published 2008-01-09

CVE-2007-6601: The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident…

PriorityP433high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
1.57%
72.7th percentile
The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2007-3278.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
postgresqlpostgresql
postgresqlpostgresql>= 7.3.0 < 7.3.217.3.21
postgresqlpostgresql>= 7.4.0 < 7.4.197.4.19
postgresqlpostgresql>= 8.0.0 < 8.0.158.0.15
postgresqlpostgresql>= 8.1.0 < 8.1.118.1.11
postgresqlpostgresql>= 8.2.0 < 8.2.68.2.6

CVSS provenance

nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat6.9MEDIUM
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.