CVE-2007-6601

Postgresql < 7.3.21 - Authentication Bypass

Title source: rule

Description

The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2007-3278.

Scores

EPSS 0.0071
EPSS Percentile 72.0%

Classification

CWE
CWE-287
Status draft

Affected Products (6)

postgresql/postgresql < 7.3.21
postgresql/postgresql
debian/debian_linux
debian/debian_linux
fedoraproject/fedora
fedoraproject/fedora

Timeline

Published Jan 09, 2008
Tracked Since Feb 18, 2026