6.8
CVSSv2

CVE-2009-3231

Published: 17/09/2009 Updated: 13/02/2024
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 607
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The core server component in PostgreSQL 8.3 prior to 8.3.8 and 8.2 prior to 8.2.14, when using LDAP authentication with anonymous binds, allows remote malicious users to bypass authentication via an empty password.

Vulnerable Product Search on Vulmon Subscribe to Product

postgresql postgresql

suse linux enterprise server 9

suse linux enterprise 11.0

opensuse opensuse

suse linux enterprise 10.0

fedoraproject fedora 11

fedoraproject fedora 10

canonical ubuntu linux 9.04

canonical ubuntu linux 8.10

canonical ubuntu linux 8.04

canonical ubuntu linux 6.06

Vendor Advisories

It was discovered that PostgreSQL could be made to unload and reload an already loaded module by using the LOAD command A remote authenticated attacker could exploit this to cause a denial of service This issue did not affect Ubuntu 606 LTS (CVE-2009-3229) ...
Several vulnerabilities have been discovered in PostgreSQL, an SQL database system The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-3229 Authenticated users can shut down the backend server by re-LOAD-ing libraries in $libdir/plugins, if any libraries are present there (The old stable distribution (etc ...