Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Gentoo Local Security Checks >> [GLSA-200506-02] Mailutils: SQL Injection


Vulnerability Assessment Details

[GLSA-200506-02] Mailutils: SQL Injection

Vulnerability Assessment Summary
Mailutils: SQL Injection

Detailed Explanation for this Vulnerability Assessment
The remote host is affected by the vulnerability described in GLSA-200506-02
(Mailutils: SQL Injection)


When GNU Mailutils is built with the "mysql" or "postgres" USE
flag, the sql_escape_string function of the authentication module fails
to properly escape the "\" character, rendering it vulnerable to a SQL
command injection.

Impact

A malicious remote user could exploit this vulnerability to inject
SQL commands to the underlying database.

Workaround

There is no known workaround at this time.

References:
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1824


Solution:
All GNU Mailutils users should upgrade to the latest available
version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-mail/mailutils-0.6-r1"


Network Security Threat Level: Medium


Networks Security ID:

Vulnerability Assessment Copyright: (C) 2005 Michel Arboi

Cables, Connectors


INTEL XEON PLATINUM 8260 PROCESSOR | 2.40GHZ | SRF9H picture

INTEL XEON PLATINUM 8260 PROCESSOR | 2.40GHZ | SRF9H

$159.99



Intel Xeon E5-2699 v3 2.3GHz 18-Core CPU/Processor SR1XD      @ X picture

Intel Xeon E5-2699 v3 2.3GHz 18-Core CPU/Processor SR1XD @ X

$35.00



Intel Xeon E5-2696v4 2.20GHz 22 Core 55MB 145W FCLGA2011-3 CPU SR2J0 picture

Intel Xeon E5-2696v4 2.20GHz 22 Core 55MB 145W FCLGA2011-3 CPU SR2J0

$109.95



Intel Xeon E5-2699 v3 18 Core 2.3 GHz 45MB SR1XD LGA 2011-3 B Grade CPU picture

Intel Xeon E5-2699 v3 18 Core 2.3 GHz 45MB SR1XD LGA 2011-3 B Grade CPU

$25.95



Dell Precision 3630 Tower Xeon(R) E-2146G @ 3.50GHz 16GB DDR4 500GB SSD NO OS picture

Dell Precision 3630 Tower Xeon(R) E-2146G @ 3.50GHz 16GB DDR4 500GB SSD NO OS

$219.99



2 Intel Xeon E5-2697 V3 SR1XF 2.60GHz 14-Core CPU Processor Lot picture

2 Intel Xeon E5-2697 V3 SR1XF 2.60GHz 14-Core CPU Processor Lot

$12.99



Intel Xeon E5-2680 V4 Processor (2.4 GHz, 14 Cores, LGA 2011-3) - SR2N7 picture

Intel Xeon E5-2680 V4 Processor (2.4 GHz, 14 Cores, LGA 2011-3) - SR2N7

$11.98



INTEL XEON E5-2695V4 SR2J1 2.10GHZ CPU PROCESSOR picture

INTEL XEON E5-2695V4 SR2J1 2.10GHZ CPU PROCESSOR

$24.99



HP Z640 Tower Workstation Xeon E5 240GB SSD+1TB HDD 64GB RAM NVIDIA Quadro K2200 picture

HP Z640 Tower Workstation Xeon E5 240GB SSD+1TB HDD 64GB RAM NVIDIA Quadro K2200

$239.99



Lenovo ThinkSystem ST50 Workstation Intel Xeon E-2126G 32GB RAM 1TB HDD No OS picture

Lenovo ThinkSystem ST50 Workstation Intel Xeon E-2126G 32GB RAM 1TB HDD No OS

$249.99



Discussions

No Discussions have been posted on this vulnerability.