CVE-2009-3231
17.09.2009, 10:30
The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.Enginsight
| Vendor | Product | Version |
|---|---|---|
| postgresql | postgresql | 8.2 ≤ 𝑥 < 8.2.14 |
| postgresql | postgresql | 8.3 ≤ 𝑥 < 8.3.8 |
| opensuse | opensuse | 10.3 ≤ 𝑥 ≤ 11.1 |
| suse | linux_enterprise | 10.0:sp2 |
| suse | linux_enterprise | 11.0 |
| canonical | ubuntu_linux | 6.06 |
| canonical | ubuntu_linux | 8.04 |
| canonical | ubuntu_linux | 8.10 |
| canonical | ubuntu_linux | 9.04 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References