CVE-2009-3231

The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html Mailing List
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html Mailing List
http://marc.info/?l=bugtraq&m=134124585221119&w=2 Mailing List
http://marc.info/?l=bugtraq&m=134124585221119&w=2 Mailing List
http://secunia.com/advisories/36660 Broken Link Vendor Advisory
http://secunia.com/advisories/36727 Broken Link Vendor Advisory
http://secunia.com/advisories/36800 Broken Link
http://secunia.com/advisories/36837 Broken Link
http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0012 Broken Link
http://www.postgresql.org/docs/8.3/static/release-8-3-8.html Release Notes
http://www.postgresql.org/support/security.html Broken Link Vendor Advisory
http://www.securityfocus.com/archive/1/509917/100/0/threaded Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/36314 Broken Link Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/usn-834-1 Third Party Advisory
http://www.us.debian.org/security/2009/dsa-1900 Broken Link
https://bugzilla.redhat.com/show_bug.cgi?id=522084 Issue Tracking Patch
https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00305.html Mailing List
https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00307.html Mailing List
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html Mailing List
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html Mailing List
http://marc.info/?l=bugtraq&m=134124585221119&w=2 Mailing List
http://marc.info/?l=bugtraq&m=134124585221119&w=2 Mailing List
http://secunia.com/advisories/36660 Broken Link Vendor Advisory
http://secunia.com/advisories/36727 Broken Link Vendor Advisory
http://secunia.com/advisories/36800 Broken Link
http://secunia.com/advisories/36837 Broken Link
http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0012 Broken Link
http://www.postgresql.org/docs/8.3/static/release-8-3-8.html Release Notes
http://www.postgresql.org/support/security.html Broken Link Vendor Advisory
http://www.securityfocus.com/archive/1/509917/100/0/threaded Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/36314 Broken Link Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/usn-834-1 Third Party Advisory
http://www.us.debian.org/security/2009/dsa-1900 Broken Link
https://bugzilla.redhat.com/show_bug.cgi?id=522084 Issue Tracking Patch
https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00305.html Mailing List
https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00307.html Mailing List
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:opensuse:opensuse:*:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise:10.0:sp2:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise:11.0:-:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:9:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:fedoraproject:fedora:10:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:11:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*

History

No history.

Information

Published : 2009-09-17 10:30

Updated : 2025-04-09 00:30


NVD link : CVE-2009-3231

Mitre link : CVE-2009-3231

CVE.ORG link : CVE-2009-3231


JSON object : View

Products Affected

postgresql

  • postgresql

opensuse

  • opensuse

fedoraproject

  • fedora

suse

  • linux_enterprise_server
  • linux_enterprise

canonical

  • ubuntu_linux
CWE
CWE-287

Improper Authentication