Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.68871
Category:Fedora Local Security Checks
Title:Fedora Core 14 FEDORA-2011-0100 (mod_auth_mysql)
Summary:NOSUMMARY
Description:Description:
The remote host is missing an update to mod_auth_mysql
announced via advisory FEDORA-2011-0100.

Update Information:

This update fixes a security issue in mod_auth_mysql.

A flaw was found in the way mod_auth_mysql escaped certain
multibyte-encoded strings. If mod_auth_mysql was configured to use a multibyte character set that allowed a backslash (\) as part of the character encodings, a remote attacker could inject arbitrary SQL commands into a login request. (CVE-2008-2384)

Note: This flaw only affected non-default installations where
AuthMySQLCharacterSet is configured to use one of the affected multibyte character sets. Installations that did not use the AuthMySQLCharacterSet configuration option were not vulnerable to this flaw.

References:

[ 1 ] Bug #480238 - CVE-2008-2384 mod_auth_mysql: character encoding SQL injection flaw
https://bugzilla.redhat.com/show_bug.cgi?id=480238

Solution: Apply the appropriate updates.

This update can be installed with the yum update program. Use
su -c 'yum update mod_auth_mysql' at the command line.
For more information, refer to Managing Software with yum,
available at http://docs.fedoraproject.org/yum/.

http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2011-0100

Risk factor : High

CVSS Score:
7.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-2384
BugTraq ID: 33392
http://www.securityfocus.com/bid/33392
http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053899.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053903.html
http://openwall.com/lists/oss-security/2009/01/21/10
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10172
http://www.redhat.com/support/errata/RHSA-2009-0259.html
http://www.redhat.com/support/errata/RHSA-2010-1002.html
http://secunia.com/advisories/33627
http://secunia.com/advisories/43302
http://www.vupen.com/english/advisories/2009/0226
http://www.vupen.com/english/advisories/2011/0367
XForce ISS Database: modauthmysql-multibyte-sql-injection(48163)
https://exchange.xforce.ibmcloud.com/vulnerabilities/48163
CopyrightCopyright (c) 2011 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.