    Debian: courier arbitrary command execution vulnerability

    Date 30 Jan 2003
    The developers of courier, an integrated user side mail server,discovered a problem in the PostgreSQL auth module.
    Debian Security Advisory DSA 247-1                     This email address is being protected from spambots. You need JavaScript enabled to view it.                             Martin Schulze
    January 30th, 2003             
    Package        : courier
    Vulnerability  : missing input sanitizing
    Problem-Type   : remote
    Debian-specific: no
    CVE Id         : CAN-2003-0040
    The developers of courier, an integrated user side mail server,
    discovered a problem in the PostgreSQL auth module.  Not all
    potentially malicious characters were sanitized before the username
    was passed to the PostgreSQL engine.  An attacker could inject
    arbitrary SQL commands and queries exploiting this vulnerability.  The
    MySQL auth module is not affected.
    For the stable distribution (woody) this problem has been fixed in
    version 0.37.3-3.3.
    The old stable distribution (potato) does not contain courier packages.
    For the unstable distribution (sid) this problem has been fixed in
    version 0.40.2-3.
    We recommend that you upgrade your courier-authpostgresql package.
    Upgrade Instructions
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    Debian GNU/Linux 3.0 alias woody
    For apt-get: deb stable/updates main
    For dpkg-ftp: dists/stable/updates/main
    Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it.
    Package info: `apt-cache show ' and

