cbcvebase.
CVE-2009-3231
published 2009-09-17

CVE-2009-3231: The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to…

medium6.8CVSS 3.1
AVNACMAuNCPIPAP
The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.

Affected

12 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
fedoraprojectfedora
fedoraprojectfedora
opensuseopensuse10.3 – 11.1
postgresqlpostgresql>= 8.2 < 8.2.148.2.14
postgresqlpostgresql>= 8.3 < 8.3.88.3.8
suselinux_enterprise
suselinux_enterprise
suselinux_enterprise_server