CVE-2009-3231
Summary
| CVE | CVE-2009-3231 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-09-17 10:30:01 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Postgresql | Postgresql | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 10 Update: postgresql-8.3.8-1.fc10 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Mailing List |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:017 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| '[security bulletin] HPSBMU02781 SSRT100617 rev.1 - HP Network Node Manager i (NNMi) for HP-UX, Linux' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Mailing List |
| Debian update for postgresql - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| PostgreSQL Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| USN-834-1: PostgreSQL vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| [SECURITY] Fedora 11 Update: postgresql-8.3.8-1.fc11 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Mailing List |
| PostgreSQL: Documentation: Manuals: PostgreSQL 8.3: Release 8.3.8 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Release Notes |
| Fedora update for postgresql - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| wiki.rpath.com/wiki/Advisories:rPSA-2010-0012 | af854a3a-2127-422b-91ae-364da2661108 | wiki.rpath.com | Broken Link |
| PostgreSQL: Security Information | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Broken Link, Vendor Advisory |
| Security Advisory SA36800 - Ubuntu update for postgresql - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| PostgreSQL Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| Debian -- Security Information -- DSA-1900-1 postgresql-7.4, postgresql-8.1, postgresql-8.3, postgresql-8.4 | af854a3a-2127-422b-91ae-364da2661108 | www.us.debian.org | Broken Link |
| Bug 522084 – CVE-2009-3231 postgresql: LDAP authentication bypass when anonymous LDAP bind are allowed | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Patch |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:016 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-09-24 | Tomas Hoger | Not vulnerable. This issue did not affect the versions of PostgreSQL as shipped with Red Hat Enterprise Linux 3, 4, or 5, as they do not support LDAP authentication, which was introduced upstream in version 8.2. This issue was addressed in Red Hat Application Stack v2 via https://rhn.redhat.com/errata/RHSA-2009-1461.html . |
There are currently no legacy QID mappings associated with this CVE.