CVE-2007-3278
Summary
| CVE | CVE-2007-3278 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-06-19 21:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Postgresql | Postgresql | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Gentoo Linux Documentation -- PostgreSQL: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | Third Party Advisory |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| USN-568-1: PostgreSQL vulnerabilities | Ubuntu security notices | af854a3a-2127-422b-91ae-364da2661108 | usn.ubuntu.com | Third Party Advisory |
| Mandriva update for postgresql - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Debian update for postgresql-7.4 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| HP Internet Express for Tru64 UNIX Multiple PostgreSQL Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| Advisories | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| Debian -- Security Information -- DSA-1460-1 postgresql-8.1 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| www.leidecker.info/pgshell/Having_Fun_With_PostgreSQL.txt | af854a3a-2127-422b-91ae-364da2661108 | www.leidecker.info | Third Party Advisory |
| Red Hat update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp | af854a3a-2127-422b-91ae-364da2661108 | h20000.www2.hp.com | Third Party Advisory |
| Sun Solaris 10 PostgreSQL Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| Support | Red Hat | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| Red Hat update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Ubuntu update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Broken Link |
| osvdb.org/40899 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| Debian update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Broken Link |
| Gentoo update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Debian -- Security Information -- DSA-1463-1 postgresql-7.4 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | www.portcullis.co.uk | Third Party Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2008-02-01 | Mark J Cox | Red Hat does not consider this do be a security issue. dblink is disabled in default configuration of PostgreSQL packages as shipped with Red Hat Enterprise Linux versions 2.1, 3, 4 and 5, and it is a configuration decision whether to grant local users arbitrary access. Fixes to correct this bug were included in PostgreSQL updates: http:rhn.redhat.comcveCVE-2007-3278.html |
There are currently no legacy QID mappings associated with this CVE.