CVE Vulnerabilities

CVE-2005-1824

Published: Jun 02, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The sql_escape_string function in auth/sql.c for the mailutils SQL authentication module does not properly quote the (backslash) character, which is used as an escape character and makes the module vulnerable to SQL injection attacks.

Affected Software

NameVendorStart VersionEnd Version
MailutilsGnu1.0.6.1.1 (including)1.0.6.1.1 (including)
MailutilsUbuntudapper*
MailutilsUbuntudevel*
MailutilsUbuntuedgy*
MailutilsUbuntufeisty*

References