CVE-2009-3231
N/A
N/A
Summary
The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00307.html
- http://www.postgresql.org/docs/8.3/static/release-8-3-8.html
- http://www.securityfocus.com/bid/36314
- http://marc.info/?l=bugtraq&m=134124585221119&w=2
- http://secunia.com/advisories/36837
- http://www.postgresql.org/support/security.html
- http://secunia.com/advisories/36660
- http://www.securityfocus.com/archive/1/509917/100/0/threaded
- http://secunia.com/advisories/36800
- http://www.us.debian.org/security/2009/dsa-1900
- https://bugzilla.redhat.com/show_bug.cgi?id=522084
- https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00305.html
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html
- http://secunia.com/advisories/36727
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html
- http://www.ubuntu.com/usn/usn-834-1
- http://marc.info/?l=bugtraq&m=134124585221119&w=2
- http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0012
References
- https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00307.html
- http://www.postgresql.org/docs/8.3/static/release-8-3-8.html
- http://www.securityfocus.com/bid/36314
- http://marc.info/?l=bugtraq&m=134124585221119&w=2
- http://secunia.com/advisories/36837
- http://www.postgresql.org/support/security.html
- http://secunia.com/advisories/36660
- http://www.securityfocus.com/archive/1/509917/100/0/threaded
- http://secunia.com/advisories/36800
- http://www.us.debian.org/security/2009/dsa-1900
- https://bugzilla.redhat.com/show_bug.cgi?id=522084
- https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00305.html
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html
- http://secunia.com/advisories/36727
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html
- http://www.ubuntu.com/usn/usn-834-1
- http://marc.info/?l=bugtraq&m=134124585221119&w=2
- http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0012
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.