CVE-2009-3231

NameCVE-2009-3231
DescriptionThe core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-1900-1

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
postgresql-7.4sourceetch1:7.4.26-0etch1DSA-1900-1
postgresql-7.4source(unstable)(not affected)
postgresql-8.1sourceetch8.1.18-0etch1DSA-1900-1
postgresql-8.1source(unstable)(not affected)
postgresql-8.3sourcelenny8.3.8-0lenny1DSA-1900-1
postgresql-8.3source(unstable)8.3.8-1
postgresql-8.4source(unstable)8.4.1-1

Search for package or bug name: Reporting problems