First published: Tue May 23 2017(Updated: )
PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user via an unknown username.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
debounce | =1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6817 is classified as a medium severity vulnerability due to its potential for remote unauthorized access.
To fix CVE-2015-6817, upgrade PgBouncer to version 1.6.1 or later.
CVE-2015-6817 affects PgBouncer versions 1.6.x prior to 1.6.1.
Yes, CVE-2015-6817 can be exploited remotely by attackers leveraging the auth_user configuration.
Attackers can gain unauthorized login access as auth_user due to the vulnerability in CVE-2015-6817.