CVE-2009-3231

EUVD-2009-3214
The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
Affected Products (NVD)
VendorProductVersion
postgresqlpostgresql
8.2 ≤
𝑥
< 8.2.14
postgresqlpostgresql
8.3 ≤
𝑥
< 8.3.8
opensuseopensuse
10.3 ≤
𝑥
≤ 11.1
suselinux_enterprise
10.0:sp2
suselinux_enterprise
11.0
canonicalubuntu_linux
6.06
canonicalubuntu_linux
8.04
canonicalubuntu_linux
8.10
canonicalubuntu_linux
9.04
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
postgresql-8.3
dapper
dne
hardy
Fixed 8.3.8-0ubuntu8.04
released
intrepid
Fixed 8.3.8-0ubuntu8.10
released
jaunty
Fixed 8.3.8-0ubuntu9.04
released
References