LWN.net Logo

courier-authlib: SQL injection

Package(s):courier-authlib CVE #(s):CVE-2008-2667
Created:September 8, 2008 Updated:December 26, 2008
Description:

From the Gentoo advisory:

It has been discovered that some input (e.g. the username) passed to the library are not properly sanitised before being used in SQL queries.

A remote attacker could provide specially crafted input to the library, possibly resulting in the remote execution of arbitrary SQL commands. NOTE: Exploitation of this vulnerability requires that a MySQL database is used for authentication and that a Non-Latin character set is selected.

Alerts:
Debian DSA-1688-2 2008-12-22
Debian DSA-1688 2008-12-20
Gentoo 200809-05 2008-09-05

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds