First published: Mon Dec 22 2008(Updated: )
SQL injection vulnerability in authpgsqllib.c in Courier-Authlib before 0.62.0, when a non-Latin locale Postgres database is used, allows remote attackers to execute arbitrary SQL commands via query parameters containing apostrophes.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Courier MTA | =0.60.5 | |
Courier MTA | =0.61.0 | |
Courier MTA | =0.60 | |
Courier MTA | =0.52 | |
Courier MTA | =0.58 | |
Courier MTA | =0.59.1 | |
Courier MTA | =0.60.1 | |
Courier MTA | =0.60.6 | |
Courier MTA | =0.56 | |
Courier MTA | =0.59.3 | |
Courier MTA | =0.53 | |
Courier MTA | =0.59.2 | |
Courier MTA | =0.57 | |
Courier MTA | =0.55 | |
Courier MTA | =0.60.4 | |
Courier MTA | =0.61.1 | |
Courier MTA | =0.59 | |
Courier MTA | =0.54 | |
Courier MTA | =0.60.2 | |
Courier MTA | =0.60.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2380 is considered to have a significant security impact due to the potential for remote SQL injection.
To fix CVE-2008-2380, update Courier-Authlib to version 0.62.0 or later.
The affected versions for CVE-2008-2380 include Courier-Authlib versions from 0.52 to 0.61.0.
CVE-2008-2380 allows remote attackers to execute arbitrary SQL commands through crafted query parameters.
CVE-2008-2380 is specifically vulnerable when using a non-Latin locale Postgres database.