CVE-2008-2667: SQL Injection
SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0.60.6 on SUSE openSUSE 10.3 and 11.0, and other platforms, when MySQL and a non-Latin character set are used, allows remote attackers to execute arbitrary SQL commands via the username and unspecified other vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2667?
CVE-2008-2667 has a medium severity level due to its potential for SQL injection attacks.
How do I fix CVE-2008-2667?
To fix CVE-2008-2667, you should upgrade the Courier Authentication Library to version 0.60.6 or later.
Who is affected by CVE-2008-2667?
CVE-2008-2667 affects users of Courier Authentication Library versions 0.52 through 0.60.5 on platforms like SUSE openSUSE 10.3 and 11.0.
What kind of attack can CVE-2008-2667 lead to?
CVE-2008-2667 can lead to remote attackers executing arbitrary SQL commands on vulnerable systems.
Can MySQL with non-Latin character sets exploit CVE-2008-2667?
Yes, CVE-2008-2667 specifically affects setups using MySQL along with non-Latin character sets, increasing the risk of exploitation.