CVE-2009-3231
published 2009-09-17CVE-2009-3231: The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to…
PriorityP353medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
7.57%
93.9th percentile
The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | opensuse | 10.3 – 11.1 | — |
| postgresql | postgresql | >= 8.2 < 8.2.14 | 8.2.14 |
| postgresql | postgresql | >= 8.3 < 8.3.8 | 8.3.8 |
| suse | linux_enterprise | — | — |
| suse | linux_enterprise | — | — |
| suse | linux_enterprise_server | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gx42-wp82-42x7: The core server component in PostgreSQL 8
ghsa_unreviewed·2022-05-02
CVE-2009-3231 [MEDIUM] CWE-287 GHSA-gx42-wp82-42x7: The core server component in PostgreSQL 8
The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2009-09-21·CVSS 6.5
CVE-2009-3229 [MEDIUM] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: PostgreSQL vulnerabilities
It was discovered that PostgreSQL could be made to unload and reload an
already loaded module by using the LOAD command. A remote authenticated
attacker could exploit this to cause a denial of service. This issue did
not affect Ubuntu 6.06 LTS. (CVE-2009-3229)
Due to an incomplete fix for CVE-2007-6600, RESET ROLE and RESET SESSION
AUTHORIZATION operations were allowed inside security-definer functions. A
remote authenticated attacker could exploit this to escalate privileges
within PostgreSQL. (CVE-2009-3230)
It was discovered that PostgreSQL did not properly perform LDAP
authentication under certain circumstances. When configured to use LDAP
with anonymous binds, a remote attacker could bypass authentication by
sup
Red Hat
postgresql: LDAP authentication bypass when anonymous LDAP bind are allowed
vendor_redhat·2009-09-09·CVSS 6.8
CVE-2009-3231 [MEDIUM] postgresql: LDAP authentication bypass when anonymous LDAP bind are allowed
postgresql: LDAP authentication bypass when anonymous LDAP bind are allowed
The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
Statement: Not vulnerable. This issue did not affect the versions of PostgreSQL as shipped with Red Hat Enterprise Linux 3, 4, or 5, as they do not support LDAP authentication, which was introduced upstream in version 8.2.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.htmlhttp://marc.info/?l=bugtraq&m=134124585221119&w=2http://secunia.com/advisories/36660http://secunia.com/advisories/36727http://secunia.com/advisories/36800http://secunia.com/advisories/36837http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0012http://www.postgresql.org/docs/8.3/static/release-8-3-8.htmlhttp://www.postgresql.org/support/security.htmlhttp://www.securityfocus.com/archive/1/509917/100/0/threadedhttp://www.securityfocus.com/bid/36314http://www.ubuntu.com/usn/usn-834-1http://www.us.debian.org/security/2009/dsa-1900https://bugzilla.redhat.com/show_bug.cgi?id=522084https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00305.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-September/msg00307.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.htmlhttp://marc.info/?l=bugtraq&m=134124585221119&w=2http://secunia.com/advisories/36660http://secunia.com/advisories/36727http://secunia.com/advisories/36800http://secunia.com/advisories/36837http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0012http://www.postgresql.org/docs/8.3/static/release-8-3-8.htmlhttp://www.postgresql.org/support/security.htmlhttp://www.securityfocus.com/archive/1/509917/100/0/threadedhttp://www.securityfocus.com/bid/36314http://www.ubuntu.com/usn/usn-834-1http://www.us.debian.org/security/2009/dsa-1900https://bugzilla.redhat.com/show_bug.cgi?id=522084https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00305.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-September/msg00307.html
2009-09-17
Published