SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0.60.6 on SUSE openSUSE 10.3 and 11.0, and other platforms, when MySQL and a non-Latin character set are used, allows remote attackers to execute arbitrary SQL commands via the username and unspecified other vectors.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade courier-authlib | Jul 30, 2024 | Jul 7, 2008 |
| Gentoo Linux | — | Upgrade net-libs/courier-authlib. | Oct 30, 2017 | Jul 7, 2008 |
| Suse | — | Upgrade suse-releaseUpgrade courier-authlib-userdbUpgrade courier-authlib-mysqlUpgrade courier-authlib-ldapUpgrade courier-authlibUpgrade courier-authlib-pgsqlUpgrade courier-authlib-develUpgrade courier-authlib-pipe | Feb 17, 2015 | Jul 7, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub