The sql_escape_string function in auth/sql.c for the mailutils SQL authentication module does not properly quote the (backslash) character, which is used as an escape character and makes the module vulnerable to SQL injection attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mailutils | Gnu | 1.0.6.1.1 (including) | 1.0.6.1.1 (including) |
Mailutils | Ubuntu | dapper | * |
Mailutils | Ubuntu | devel | * |
Mailutils | Ubuntu | edgy | * |
Mailutils | Ubuntu | feisty | * |