Back to Vulnerability Directory
HIGHFixed upstream

CVE-2002-1657

PostgreSQL uses the username for a salt when generating passwords, which makes it easier for…

Technology

PostgreSQL

CVSS Score

7.5 / 10.0

Affected Versions

7.3.19

Upstream Fix

See upstream advisory

Published

December 31, 2002

OSSeva Coverage

Fixed upstream

Description

PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.

Is your PostgreSQL deployment affected?

If you're running 7.3.19, you need this patch. Book a discovery call to get covered.