CVE Vulnerabilities

CVE-2005-1824

Published: Jun 02, 2005 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The sql_escape_string function in auth/sql.c for the mailutils SQL authentication module does not properly quote the (backslash) character, which is used as an escape character and makes the module vulnerable to SQL injection attacks.

Affected Software

Name Vendor Start Version End Version
Mailutils Gnu 1.0.6.1.1 (including) 1.0.6.1.1 (including)
Mailutils Ubuntu dapper *
Mailutils Ubuntu devel *
Mailutils Ubuntu edgy *
Mailutils Ubuntu feisty *

References