CVE-2007-6601

CVSS V2 High 7.2 CVSS V3 None
Description
The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2007-3278.
Overview
  • CVE ID
  • CVE-2007-6601
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2008-01-09T21:46:00
  • Last Modified Date
  • 2023-01-18T21:19:30
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:postgresql:postgresql:7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.3.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.3.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.3.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.3.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.3.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.3.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.3.9:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.3.10:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.3.11:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.3.12:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.3.13:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.3.14:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.3.15:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.3.16:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.3.19:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.4.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.4.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.4.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.4.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.4.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.4.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.4.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.4.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.4.9:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.4.10:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.4.11:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.4.12:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.4.13:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.4.14:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.4.16:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:7.4.17:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.0.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.0.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.0.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.0.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.0.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.0.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.0.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.0.9:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.0.11:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.0.13:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.0.317:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.1.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.1.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.1.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.1.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.1.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.1.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.1.9:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.2.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.2.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:postgresql:postgresql:8.2.4:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:L/AC:L/Au:N/C:C/I:C/A:C
  • Access Vector
  • LOCAL
  • Access Compatibility
  • LOW
  • Authentication
  • NONE
  • Confidentiality Impact
  • COMPLETE
  • Integrity Impact
  • COMPLETE
  • Availability Impact
  • COMPLETE
  • Base Score
  • 7.2
  • Severity
  • HIGH
  • Exploitability Score
  • 3.9
  • Impact Score
  • 10
References
Reference URL Reference Tags
http://www.postgresql.org/about/news.905
http://www.securityfocus.com/bid/27163 Patch
http://securitytracker.com/id?1019157
http://secunia.com/advisories/28359 Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2008:004
https://issues.rpath.com/browse/RPL-1768
http://www.debian.org/security/2008/dsa-1460
http://www.debian.org/security/2008/dsa-1463
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00397.html
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00469.html
http://www.redhat.com/support/errata/RHSA-2008-0038.html
http://www.redhat.com/support/errata/RHSA-2008-0039.html
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103197-1
http://secunia.com/advisories/28376
http://secunia.com/advisories/28438
http://secunia.com/advisories/28445
http://secunia.com/advisories/28437
http://secunia.com/advisories/28454
http://secunia.com/advisories/28464
http://secunia.com/advisories/28477
http://secunia.com/advisories/28479
http://secunia.com/advisories/28455
http://security.gentoo.org/glsa/glsa-200801-15.xml
http://secunia.com/advisories/28679
http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00000.html
http://secunia.com/advisories/28698
http://www.redhat.com/support/errata/RHSA-2008-0040.html
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200559-1
http://secunia.com/advisories/29638
http://www.vupen.com/english/advisories/2008/1071/references
http://www.vupen.com/english/advisories/2008/0109
http://www.vupen.com/english/advisories/2008/0061
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154
https://exchange.xforce.ibmcloud.com/vulnerabilities/39500
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11127
https://usn.ubuntu.com/568-1/
http://www.securityfocus.com/archive/1/486407/100/0/threaded
http://www.securityfocus.com/archive/1/485864/100/0/threaded
History
Created Old Value New Value Data Type Notes
2022-05-10 18:19:08 Added to TrackCVE
2023-01-18 20:02:03 Modified Undergoing Analysis Vulnerability Status updated
2023-01-18 23:01:58 2023-01-18T21:19:30 CVE Modified Date updated
2023-01-18 23:01:58 Undergoing Analysis Analyzed Vulnerability Status updated