CVE-2007-6601
Summary
| CVE | CVE-2007-6601 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-01-09 21:46:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2007-3278. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Postgresql | Postgresql | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Gentoo Linux Documentation -- PostgreSQL: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | Third Party Advisory |
| Support / Security / Advisories / / MDVSA-2008:004 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Broken Link |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| SUSE update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| USN-568-1: PostgreSQL vulnerabilities | Ubuntu security notices | af854a3a-2127-422b-91ae-364da2661108 | usn.ubuntu.com | Broken Link |
| SecurityTracker.com Archives - PostgreSQL Bugs Let Remote Authenticated Users Deny Service and Obtain Elevated Privileges | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| Mandriva update for postgresql - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| Fedora update for postgresql - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| Debian update for postgresql-7.4 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| PostgreSQL Multiple Privilege Escalation and Denial of Service Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Third Party Advisory, VDB Entry |
| HP Internet Express for Tru64 UNIX Multiple PostgreSQL Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| PostgreSQL Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable, Vendor Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required, Third Party Advisory |
| [SECURITY] Fedora 8 Update: postgresql-8.2.6-1.fc8 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Mailing List, Third Party Advisory |
| rPath update for postgresql and postgresql-server - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| Debian -- Security Information -- DSA-1460-1 postgresql-8.1 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| Red Hat update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| issues.rpath.com/browse/RPL-1768 | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | Broken Link |
| [security-announce] SUSE Security Announcement: PostgreSQL security issu | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Broken Link |
| h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp | af854a3a-2127-422b-91ae-364da2661108 | h20000.www2.hp.com | Broken Link |
| Sun Solaris 10 PostgreSQL Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| Support | Red Hat | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| Red Hat update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| Ubuntu update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Broken Link |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Debian update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| [SECURITY] Fedora 7 Update: postgresql-8.2.6-1.fc7 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Mailing List, Third Party Advisory |
| PostgreSQL: News: 2008-01-07 Cumulative Security Update Release | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Broken Link |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Broken Link |
| Gentoo update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| Debian -- Security Information -- DSA-1463-1 postgresql-7.4 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.