Lucene search

K
ubuntucveUbuntu.comUB:CVE-2007-3278
HistoryJun 19, 2007 - 12:00 a.m.

CVE-2007-3278

2007-06-1900:00:00
ubuntu.com
ubuntu.com
9

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

0.003 Low

EPSS

Percentile

70.1%

PostgreSQL 8.1 and probably later versions, when local trust authentication
is enabled and the Database Link library (dblink) is installed, allows
remote attackers to access arbitrary accounts and execute arbitrary SQL
queries via a dblink host parameter that proxies the connection from
127.0.0.1.

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

0.003 Low

EPSS

Percentile

70.1%