Upstream information
CVE-2008-2380 at MITRE
Description
SQL injection vulnerability in authpgsqllib.c in Courier-Authlib before 0.62.0, when a non-Latin locale Postgres database is used, allows remote attackers to execute arbitrary SQL commands via query parameters containing apostrophes.
Novell/SUSE information
Novell Bugzilla entry:
457238
SUSE Security Advisories:
List of released packages
| Product(s) | Fixed package version(s) | References |
| openSUSE 10.3 | courier-authlib >= 0.59.3-44.4 courier-authlib-devel >= 0.59.3-44.4 courier-authlib-ldap >= 0.59.3-44.4 courier-authlib-mysql >= 0.59.3-44.4 courier-authlib-pgsql >= 0.59.3-44.4 courier-authlib-pipe >= 0.59.3-44.4 courier-authlib-userdb >= 0.59.3-44.4
| |