5

CVE-2005-4713

Unspecified vulnerability in the SQL logging facility in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors, probably involving the pam_mysql_sql_log function when being used in vsftpd, which does not include the IP address argument to an sprintf call.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pam MysqlPam Mysql Version0.1
Pam MysqlPam Mysql Version0.2
Pam MysqlPam Mysql Version0.3
Pam MysqlPam Mysql Version0.4
Pam MysqlPam Mysql Version0.4.7
Pam MysqlPam Mysql Version0.5
Pam MysqlPam Mysql Version0.6
Pam MysqlPam Mysql Version0.7_pre1
Pam MysqlPam Mysql Version0.7_pre2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.85% 0.764
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/18598
Patch
Vendor Advisory
http://secunia.com/advisories/20690
http://sourceforge.net/forum/forum.php?forum_id=499394
Patch
http://sourceforge.net/tracker/index.php?func=detail&aid=1256243&group_id=5741&atid=305741
http://www.gentoo.org/security/en/glsa/glsa-200606-18.xml
http://www.securityfocus.com/bid/16564
Patch
http://www.vupen.com/english/advisories/2006/0490