CVE-2007-3280
Publication date 19 June 2007
Last updated 17 July 2025
Ubuntu priority
The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the C programming language, which allows remote authenticated superusers to map and execute a function from any library, as demonstrated by using the system function in libc.so.6 to gain shell access.
Status
Package | Ubuntu Release | Status |
---|---|---|
postgresql-8.1 | ||
postgresql-8.2 | ||