Updated mod_auth_pgsql packages are now available for Red Hat Linux 7.2. These updates close a vulnerability which would allow a malicious client to cause a Web server to execute arbitrary SQL statements. A bug in the MD5 password mechanism causing valid passwords not to authenticate the user has also been fixed.
The updated mod_auth_pgsql packages close a vulnerability which would allow a malicious client to cause a Web server to execute arbitrary SQL statements. Several Apache authentication modules which use SQL databases to store authentication information are vulnerable to a remote SQL code injection attack. A bug in the MD5 password mechanism causing valid passwords not to authenticate the user has also been fixed.
With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.
– Scott Cheney, Manager of Information Security, Sierra View Medical Center