PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2017:2728 | third party advisory vendor advisory |
http://www.debian.org/security/2017/dsa-3936 | third party advisory vendor advisory |
https://access.redhat.com/errata/RHSA-2017:2678 | third party advisory vendor advisory |
https://access.redhat.com/errata/RHSA-2017:2860 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/100278 | vdb entry third party advisory |
http://www.debian.org/security/2017/dsa-3935 | third party advisory vendor advisory |
http://www.securitytracker.com/id/1039142 | vdb entry third party advisory |
https://www.postgresql.org/about/news/1772/ | vendor advisory |
https://security.gentoo.org/glsa/201710-06 | third party advisory vendor advisory |
https://access.redhat.com/errata/RHSA-2017:2677 | third party advisory vendor advisory |