CVE-2017-7485
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/05/2017
Last modified:
20/04/2025
Description
In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-in-the-Middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server.
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:postgresql:postgresql:9.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:9.3.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:9.3.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:9.3.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:9.3.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:9.3.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:9.3.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:9.3.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:9.3.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:9.3.9:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:9.3.10:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:9.3.11:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:9.3.12:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:9.3.13:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:9.3.14:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.debian.org/security/2017/dsa-3851
- http://www.securityfocus.com/bid/98461
- http://www.securitytracker.com/id/1038476
- https://access.redhat.com/errata/RHSA-2017:1677
- https://access.redhat.com/errata/RHSA-2017:1678
- https://access.redhat.com/errata/RHSA-2017:1838
- https://access.redhat.com/errata/RHSA-2017:2425
- https://security.gentoo.org/glsa/201710-06
- https://www.postgresql.org/about/news/1746/
- http://www.debian.org/security/2017/dsa-3851
- http://www.securityfocus.com/bid/98461
- http://www.securitytracker.com/id/1038476
- https://access.redhat.com/errata/RHSA-2017:1677
- https://access.redhat.com/errata/RHSA-2017:1678
- https://access.redhat.com/errata/RHSA-2017:1838
- https://access.redhat.com/errata/RHSA-2017:2425
- https://security.gentoo.org/glsa/201710-06
- https://www.postgresql.org/about/news/1746/



