CVE-2007-6601 describes a privilege escalation vulnerability in the DBLink module of PostgreSQL versions 8.2.6 and earlier, 8.1.11 and earlier, 8.0.15 and earlier, 7.4.19 and earlier, and 7.3.21 and earlier, specifically when local trust or ident authentication is configured. This issue, an incomplete fix for CVE-2007-3278, allows remote attackers to gain elevated privileges through unspecified vectors. The vulnerability has a CVSS score of 7.2 (AV:L/AC:L/Au:N/C:C/I:C/A:C), indicating a high severity with local access, low attack complexity, and complete confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, publicly available exploit code in Metasploit, Nuclei, or ExploitDB, and it is not listed on the CISA KEV catalog. Community discussion is minimal, with only one mention found.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.3.0, < 7.3.21CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | ||
>= 7.4.0, < 7.4.19CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | ||
>= 8.0.0, < 8.0.15CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | ||
>= 8.1.0, < 8.1.11CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | ||
>= 8.2.0, < 8.2.6CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.