Gentoo: GLSA-200506-02: Mailutils: SQL Injection
Summary
Gentoo Linux Security Advisory GLSA 200506-02
https://security.gentoo.org/
Severity: Normal
Title: Mailutils: SQL Injection
Date: June 06, 2005
Bugs: #94824
ID: 200506-02
Synopsis
=======
GNU Mailutils is vulnerable to SQL command injection attacks.
Background
=========
GNU Mailutils is a collection of mail-related utilities.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-mail/mailutils < 0.6-r1 >= 0.6-r1
==========
When GNU Mailutils is built with the "mysql" or "postgres" USE flag,
the sql_escape_string function of the authentication module fails to
properly escape the "\" character, rendering it vulnerable to a SQL
command injection.
Impact
==...
Resolution
References
Availability
Concerns
Background