Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Fedora Core 3: FEDORA-2005-015 Critical: mod_auth_pgsql Remote Execution

fedora
Calendar Grey January 27, 2006
Dist Fedora Esm H88
Patch release for mod_auth_pgsql addresses vulnerabilities in format strings, enabling potential remote code exploitation. Urgent measures recommended.
Several format string flaws were found in the way mod_auth_pgsql logs information

Summary

mod_auth_pgsql can be used to limit access to documents served by a web server

by checking fields in a table in a PostgresQL database.

Several format string flaws were found in the way

mod_auth_pgsql logs information. It may be possible for a

remote attacker to execute arbitrary code as the 'apache'

user if mod_auth_pgsql is used for user authentication. The

Common Vulnerabilities and Exposures project assigned the

name CVE-2005-3656 to this issue.

Please note that this issue only affects servers which have

mod_auth_pgsql installed and configured to perform user

authentication against a PostgreSQL database.

Red Hat would like to thank iDefense for reporting this issue.

- add security fix for CVE-2005-3656

- don't strip .so file so debuginfo works

- fix r->user handling (Mirko Streckenbach, #150087)

f4de3874523d13558b62a7b616a9924b SRPMS/mod_auth_pgsql-2.0.1-6.2.src.rpm

710fe9e31a155fca650aa2e948caf3e0 x86_64/mod_auth_pgsql-2.0.1-6.2.x86_64.rpm

a98acc532d16f6824643f84681a925ba x86_64/debug/mod_auth_pgsql-debuginfo-2.0.1-6.2.x86_64.rpm

2b1130b5b5be47de09f927b2dd87bd94 i386/mod_auth_pgsql-2.0.1-6.2.i386.rpm

2d348cb3ca7f7525dce925a20fed88da i386/debug/mod_auth_pgsql-debuginfo-2.0.1-6.2.i386.rpm

This update can also be installed with the Update Agent; you can

launch the Update Agent with the 'up2date' command.

fedora-announce-list mailing list

fedora-announce-list@redhat.com

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Name: mod_auth_pgsql
Version: 2.0.1
Release: 6.2
Summary: Basic authentication for the Apache web server using a PostgreSQL database.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here