Quoting upstream PostgreSQL security page: http://www.postgresql.org/support/security.html If PostgreSQL is configured with LDAP authentication, and your LDAP configuration allows anonymous binds, it is possible for a user to authenticate themselves with an empty password. Affected versions: 8.3, 8.2 Fixed in versions: 8.3.8, 8.2.14 Severity: A - A vulnerability that is exploitable for privilege escalation without requiring a prior login.
postgresql-8.3.8-1.fc11 has been submitted as an update for Fedora 11. http://admin.fedoraproject.org/updates/postgresql-8.3.8-1.fc11
postgresql-8.3.8-1.fc10 has been submitted as an update for Fedora 10. http://admin.fedoraproject.org/updates/postgresql-8.3.8-1.fc10
postgresql-8.3.8-1.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report.
postgresql-8.3.8-1.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.
LDAP authentication support is not available in PostgreSQL packages in Red Hat Enterprise Linux 3, 4 and 5, and Red Hat Application Stack v1. PostgreSQL packages shipped in those products are not affected by this flaw.
MITRE's CVE-2009-3231 record: ----------------------------- The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password. References: ----------- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3231 http://www.postgresql.org/docs/8.3/static/release-8-3-8.html http://www.postgresql.org/support/security.html https://bugzilla.redhat.com/show_bug.cgi?id=522084 https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00305.html https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00307.html http://www.securityfocus.com/bid/36314 http://secunia.com/advisories/36660 http://secunia.com/advisories/36727
This issue has been addressed in following products: Red Hat Web Application Stack for RHEL 5 Via RHSA-2009:1461 https://rhn.redhat.com/errata/RHSA-2009-1461.html