The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Pam_mysql | Pam_mysql | 0.1 (including) | 0.1 (including) |
| Pam_mysql | Pam_mysql | 0.2 (including) | 0.2 (including) |
| Pam_mysql | Pam_mysql | 0.3 (including) | 0.3 (including) |
| Pam_mysql | Pam_mysql | 0.4 (including) | 0.4 (including) |