CVE-2009-3231
17.09.2009, 10:30
The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.Enginsight
Vendor | Product | Version |
---|---|---|
postgresql | postgresql | 8.2 ≤ 𝑥 < 8.2.14 |
postgresql | postgresql | 8.3 ≤ 𝑥 < 8.3.8 |
opensuse | opensuse | 10.3 ≤ 𝑥 ≤ 11.1 |
suse | linux_enterprise | 10.0:sp2 |
suse | linux_enterprise | 11.0 |
canonical | ubuntu_linux | 6.06 |
canonical | ubuntu_linux | 8.04 |
canonical | ubuntu_linux | 8.10 |
canonical | ubuntu_linux | 9.04 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References