10

CVE-2005-3656

Multiple format string vulnerabilities in logging functions in mod_auth_pgsql before 2.0.3, when used for user authentication against a PostgreSQL database, allows remote unauthenticated attackers to execute arbitrary code, as demonstrated via the username.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.9% 0.946
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-134 Use of Externally-Controlled Format String

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U
Patch
http://secunia.com/advisories/18517
Patch
Vendor Advisory
http://secunia.com/advisories/18463
Patch
Vendor Advisory
http://www.trustix.org/errata/2006/0002/
Patch
http://secunia.com/advisories/18304
Patch
Vendor Advisory
http://secunia.com/advisories/18321
Patch
Vendor Advisory
http://secunia.com/advisories/18347
Patch
Vendor Advisory
http://secunia.com/advisories/18348
Patch
Vendor Advisory
http://secunia.com/advisories/18350
Patch
Vendor Advisory
http://secunia.com/advisories/18397
Patch
Vendor Advisory
http://secunia.com/advisories/18403
Patch
Vendor Advisory
http://securitytracker.com/id?1015446
Patch
http://www.debian.de/security/2006/dsa-935
Patch
Vendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200601-05.xml
Patch
Vendor Advisory
http://www.giuseppetanzilli.it/mod_auth_pgsql2/
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=367
Patch
Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2006:009
http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00015.html
Patch
http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00016.html
Patch
http://www.redhat.com/support/errata/RHSA-2006-0164.html
Patch
http://www.securityfocus.com/bid/16153
Patch
http://www.vupen.com/english/advisories/2006/0070
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10600
https://usn.ubuntu.com/239-1/