SQL injection vulnerability in authpgsqllib.c in Courier-Authlib before 0.62.0, when a non-Latin locale Postgres database is used, allows remote attackers to execute arbitrary SQL commands via query parameters containing apostrophes.
CVSS Details
- CVSS 3.1 Base Score: 5.6
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade courier-authlib | Jul 30, 2024 | Dec 22, 2008 |
| Gentoo Linux | — | Upgrade net-libs/courier-authlib. | Oct 30, 2017 | Dec 22, 2008 |
| Suse | — | Upgrade courier-authlib-pipeUpgrade courier-authlib-ldapUpgrade courier-authlib-mysqlUpgrade courier-authlib-userdbUpgrade courier-authlib-pgsqlUpgrade courier-authlibUpgrade courier-authlib-devel | Feb 17, 2015 | Dec 22, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub