PostgreSQL Database Core Server non-libpq Client Policy Bypass (CVE-2017-7546)

A security policy bypass vulnerability exists in the core server component of the PostgreSQL database server. The vulnerability is due to improper authentication of user accounts with empty passwords for clients that do not use libpq. A remote attacker could send maliciously crafted requests to a vulnerable server.

from Check Point Update Services Advisories http://ift.tt/2wUhfHs

No comments:

Post a Comment

Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading

Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads...