← Back

CVE-2007-3280

nvd nist
Published: Jun 19, 2007Modified: Apr 23, 2026

JSON object

Loading...
9.0
Vector
AV:N/AC:L/Au:S/C:C/I:C/A:C
Exploitability: 8.0 / Impact: 10.0
Source: NVD

Description

The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the C programming language, which allows remote authenticated superusers to map and execute a function from any library, as demonstrated by using the system function in libc.so.6 to gain shell access.

Affected (1)

1 product
Postgresql
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.1

Timeline

No history available yet.