LWN.net Logo

pike: SQL injection vulnerability

Package(s):pike7.6 CVE #(s):CVE-2006-4041
Created:October 19, 2006 Updated:October 25, 2006
Description: Pike's PostgreSQL module has an SQL injection vulnerability. Applications that use uncommon character encodings with the PostgreSQL DBMS can be fooled into running arbitrary SQL commands, resulting in privilege escalation, data exposure or denial of service.
Alerts:
Ubuntu USN-367-1 2006-10-18

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds