Bug 522084 (CVE-2009-3231)
Summary: | CVE-2009-3231 postgresql: LDAP authentication bypass when anonymous LDAP bind are allowed | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Tomas Hoger <thoger> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | jlieskov, kaigai, ldimaggi, tgl, vdanen |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2010-03-29 10:02:35 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 522221 | ||
Bug Blocks: |
Description
Tomas Hoger
2009-09-09 13:03:29 UTC
postgresql-8.3.8-1.fc11 has been submitted as an update for Fedora 11. http://admin.fedoraproject.org/updates/postgresql-8.3.8-1.fc11 postgresql-8.3.8-1.fc10 has been submitted as an update for Fedora 10. http://admin.fedoraproject.org/updates/postgresql-8.3.8-1.fc10 postgresql-8.3.8-1.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report. postgresql-8.3.8-1.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report. LDAP authentication support is not available in PostgreSQL packages in Red Hat Enterprise Linux 3, 4 and 5, and Red Hat Application Stack v1. PostgreSQL packages shipped in those products are not affected by this flaw. MITRE's CVE-2009-3231 record: ----------------------------- The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password. References: ----------- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3231 http://www.postgresql.org/docs/8.3/static/release-8-3-8.html http://www.postgresql.org/support/security.html https://bugzilla.redhat.com/show_bug.cgi?id=522084 https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00305.html https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00307.html http://www.securityfocus.com/bid/36314 http://secunia.com/advisories/36660 http://secunia.com/advisories/36727 This issue has been addressed in following products: Red Hat Web Application Stack for RHEL 5 Via RHSA-2009:1461 https://rhn.redhat.com/errata/RHSA-2009-1461.html |