First published: Mon Jul 07 2008(Updated: )
SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0.60.6 on SUSE openSUSE 10.3 and 11.0, and other platforms, when MySQL and a non-Latin character set are used, allows remote attackers to execute arbitrary SQL commands via the username and unspecified other vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Courier MTA | =0.52 | |
Courier MTA | =0.53 | |
Courier MTA | =0.54 | |
Courier MTA | =0.55 | |
Courier MTA | =0.56 | |
Courier MTA | =0.57 | |
Courier MTA | =0.58 | |
Courier MTA | =0.59 | |
Courier MTA | =0.59.1 | |
Courier MTA | =0.59.2 | |
Courier MTA | =0.59.3 | |
Courier MTA | =0.60 | |
Courier MTA | =0.60.1 | |
Courier MTA | =0.60.2 | |
Courier MTA | =0.60.3 | |
Courier MTA | =0.60.4 | |
Courier MTA | =0.60.5 | |
SUSE Linux | =10.3 | |
SUSE Linux | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2667 has a medium severity level due to its potential for SQL injection attacks.
To fix CVE-2008-2667, you should upgrade the Courier Authentication Library to version 0.60.6 or later.
CVE-2008-2667 affects users of Courier Authentication Library versions 0.52 through 0.60.5 on platforms like SUSE openSUSE 10.3 and 11.0.
CVE-2008-2667 can lead to remote attackers executing arbitrary SQL commands on vulnerable systems.
Yes, CVE-2008-2667 specifically affects setups using MySQL along with non-Latin character sets, increasing the risk of exploitation.