CVE-2009-3231

The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
postgresqlpostgresql
8.2 ≤
𝑥
< 8.2.14
postgresqlpostgresql
8.3 ≤
𝑥
< 8.3.8
opensuseopensuse
10.3 ≤
𝑥
≤ 11.1
suselinux_enterprise
10.0:sp2
suselinux_enterprise
11.0
canonicalubuntu_linux
6.06
canonicalubuntu_linux
8.04
canonicalubuntu_linux
8.10
canonicalubuntu_linux
9.04
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
postgresql-8.3
jaunty
Fixed 8.3.8-0ubuntu9.04
released
intrepid
Fixed 8.3.8-0ubuntu8.10
released
hardy
Fixed 8.3.8-0ubuntu8.04
released
dapper
dne
References