USN-6825-1: ADOdb vulnerabilities
It was discovered that the PDO driver in ADOdb was incorrectly handling string quotes. A remote attacker could possibly use this issue to perform SQL injection attacks. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-7405) It was discovered that ADOdb was incorrectly handling GET parameters in test.php. A remote attacker could possibly use this issue to execute cross-site scripting (XSS) attacks. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-4855) Emmet Leahy discovered that ADOdb was incorrectly handling string quotes in PostgreSQL connections. A remote attacker could possibly use this issue to bypass authentication. (CVE-2021-3850)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6825-1?
USN-6825-1 is a high severity vulnerability due to potential SQL injection attacks.
How do I fix USN-6825-1?
To fix USN-6825-1, update the libphp-adodb package to version 5.20.19-1ubuntu0.1 or higher on affected Ubuntu versions.
Which Ubuntu versions are affected by USN-6825-1?
USN-6825-1 specifically affects Ubuntu 16.04 LTS among other versions.
What is the nature of the vulnerability described in USN-6825-1?
The vulnerability in USN-6825-1 involves the PDO driver in ADOdb incorrectly handling string quotes, leading to SQL injection risks.
Is the vulnerability in USN-6825-1 exploitable remotely?
Yes, a remote attacker can exploit the vulnerability in USN-6825-1 to perform SQL injection attacks.