![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.68871 |
Category: | Fedora Local Security Checks |
Title: | Fedora Core 14 FEDORA-2011-0100 (mod_auth_mysql) |
Summary: | NOSUMMARY |
Description: | Description: The remote host is missing an update to mod_auth_mysql announced via advisory FEDORA-2011-0100. Update Information: This update fixes a security issue in mod_auth_mysql. A flaw was found in the way mod_auth_mysql escaped certain multibyte-encoded strings. If mod_auth_mysql was configured to use a multibyte character set that allowed a backslash (\) as part of the character encodings, a remote attacker could inject arbitrary SQL commands into a login request. (CVE-2008-2384) Note: This flaw only affected non-default installations where AuthMySQLCharacterSet is configured to use one of the affected multibyte character sets. Installations that did not use the AuthMySQLCharacterSet configuration option were not vulnerable to this flaw. References: [ 1 ] Bug #480238 - CVE-2008-2384 mod_auth_mysql: character encoding SQL injection flaw https://bugzilla.redhat.com/show_bug.cgi?id=480238 Solution: Apply the appropriate updates. This update can be installed with the yum update program. Use su -c 'yum update mod_auth_mysql' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/. http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2011-0100 Risk factor : High CVSS Score: 7.5 |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2008-2384 BugTraq ID: 33392 http://www.securityfocus.com/bid/33392 http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053899.html http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053903.html http://openwall.com/lists/oss-security/2009/01/21/10 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10172 http://www.redhat.com/support/errata/RHSA-2009-0259.html http://www.redhat.com/support/errata/RHSA-2010-1002.html http://secunia.com/advisories/33627 http://secunia.com/advisories/43302 http://www.vupen.com/english/advisories/2009/0226 http://www.vupen.com/english/advisories/2011/0367 XForce ISS Database: modauthmysql-multibyte-sql-injection(48163) https://exchange.xforce.ibmcloud.com/vulnerabilities/48163 |
Copyright | Copyright (c) 2011 E-Soft Inc. http://www.securityspace.com |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |