{"id":"CVE-2017-7485","details":"In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-in-the-Middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server.","modified":"2026-04-16T06:20:42.148187365Z","published":"2017-05-12T19:29:00.240Z","related":["SUSE-SU-2017:1441-1","SUSE-SU-2017:1690-1","SUSE-SU-2017:1783-1"],"references":[{"type":"WEB","url":"http://www.securitytracker.com/id/1038476"},{"type":"ADVISORY","url":"http://www.debian.org/security/2017/dsa-3851"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/98461"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:1838"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201710-06"},{"type":"ADVISORY","url":"https://www.postgresql.org/about/news/1746/"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:1677"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:1678"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:2425"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7485.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"9.3"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.1"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.2"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.3"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.4"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.5"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.6"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.7"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.8"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.9"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.10"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.11"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.12"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.13"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.14"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.15"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.16"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.1"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.2"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.3"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.4"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.5"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.6"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.7"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.8"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.9"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.10"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.11"}]},{"events":[{"introduced":"0"},{"last_affected":"9.5"}]},{"events":[{"introduced":"0"},{"last_affected":"9.5.1"}]},{"events":[{"introduced":"0"},{"last_affected":"9.5.2"}]},{"events":[{"introduced":"0"},{"last_affected":"9.5.3"}]},{"events":[{"introduced":"0"},{"last_affected":"9.5.4"}]},{"events":[{"introduced":"0"},{"last_affected":"9.5.5"}]},{"events":[{"introduced":"0"},{"last_affected":"9.5.6"}]},{"events":[{"introduced":"0"},{"last_affected":"9.6"}]},{"events":[{"introduced":"0"},{"last_affected":"9.6.1"}]},{"events":[{"introduced":"0"},{"last_affected":"9.6.2"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}