[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1688 courier-authlib -- SQL injection

ID: oval:org.mitre.oval:def:8347Date: (C)2009-12-15   (M)2023-11-13
Class: PATCHFamily: unix




Two SQL injection vulnerabilities have been found in courier-authlib, the courier authentification library. The MySQL database interface used insufficient escaping mechanisms when constructing SQL statements, leading to SQL injection vulnerabilities if certain charsets are used (CVE-2008-2380). A similar issue affects the PostgreSQL database interface (CVE-2008-2667).

Platform:
Debian 4.0
Product:
courier-authlib
Reference:
DSA-1688
CVE-2008-2380
CVE-2008-2667
CVE    2
CVE-2008-2380
CVE-2008-2667
CPE    1
cpe:/o:debian:debian_linux:4.0

© SecPod Technologies