CVE-2009-3231

Description

The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
4.962

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2009-3231 are affected in Postgresql 8.3.7Windows
Vulnerabilities CVE-2009-3230,CVE-2009-3229,CVE-2009-3231 are fixed in PostgreSQL 8.3.8Windows
Vulnerabilities CVE-2009-3230,CVE-2009-3229,CVE-2009-3231 are fixed in PostgreSQL 8.2.14Windows
Vulnerability CVE-2009-3231 are affected in Postgresql 8.3.7 (For Linux)Linux
Vulnerabilities CVE-2009-3230,CVE-2009-3229,CVE-2009-3231 are fixed in PostgreSQL 8.3.8 (For Linux)Linux
Vulnerabilities CVE-2009-3230,CVE-2009-3229,CVE-2009-3231 are fixed in PostgreSQL 8.2.14 (For Linux)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234