CVE-2015-6817: High severity debounce vulnerability
Published May 23, 2017
·Updated
PgBouncer 1.6.x before 1.6.1, when configured with authuser, allows remote attackers to gain login access as authuser via an unknown username.
Affected Software
1 affected component
PgBouncer PgBouncer=1.6
Remediation
Patch Available
Patch Available
Patch Available
Event History
May 23, 2017
CVE Published
via MITRE·03:56 AM
Data Sourced
via MITRE·03:56 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6817?
CVE-2015-6817 is classified as a medium severity vulnerability due to its potential for remote unauthorized access.
2
How do I fix CVE-2015-6817?
To fix CVE-2015-6817, upgrade PgBouncer to version 1.6.1 or later.
3
What software versions are affected by CVE-2015-6817?
CVE-2015-6817 affects PgBouncer versions 1.6.x prior to 1.6.1.
4
Can CVE-2015-6817 be exploited remotely?
Yes, CVE-2015-6817 can be exploited remotely by attackers leveraging the auth_user configuration.
5
What type of attack can happen due to CVE-2015-6817?
Attackers can gain unauthorized login access as auth_user due to the vulnerability in CVE-2015-6817.