Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Debian DSA-2279-1 Critical: SQL Injection in Libapache2-mod-authnz-external

debian
Calendar Grey July 19, 2011
Debian Logo
Debian's advisory DSA-2279-1 details a patch for libapache2-mod-authnz-external addressing a SQL injection risk. Users should upgrade their packages to protect against unauthorized access.
It was discovered that libapache2-mod-authnz-external, an apache authentication module, is prone to an SQL injection via the $user paramter

Summary


For the stable distribution (squeeze), this problem has been fixed in
version 3.2.4-2+squeeze1.

The oldstable distribution (lenny) does not contain
libapache2-mod-authnz-external

For the testing distribution (wheezy), this problem will be fixed soon.

For the unstable distribution (sid), this problem has been fixed in
version 3.2.4-2.1.


We recommend that you upgrade your libapache2-mod-authnz-external packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: libapache2-mod-authnz-external
CVE ID: CVE-2011-2688

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here