Description
SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0.60.6 on SUSE openSUSE 10.3 and 11.0, and other platforms, when MySQL and a non-Latin character set are used, allows remote attackers to execute arbitrary SQL commands via the username and unspecified other vectors.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1688-1 | New courier-authlib packages fix SQL injection |
Debian DSA |
DSA-1688-2 | New courier-authlib packages fix regression |
EUVD |
EUVD-2008-2662 | SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0.60.6 on SUSE openSUSE 10.3 and 11.0, and other platforms, when MySQL and a non-Latin character set are used, allows remote attackers to execute arbitrary SQL commands via the username and unspecified other vectors. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T09:05:30.425Z
Reserved: 2008-06-10T00:00:00.000Z
Link: CVE-2008-2667
No data.
Status : Deferred
Published: 2008-07-07T23:41:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-2667
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD