Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Gentoo: 202204-01 Critical: Mailutils Buffer Overflow Vulnerability

gentoo
Calendar Grey June 6, 2005
Scroller Gentoo
The Gentoo GLSA 202112-05 outlines a moderate risk SQL injection vulnerability affecting Mailutils. Updating is advised to maintain system integrity.
GNU Mailutils is vulnerable to SQL command injection attacks.

Summary

Gentoo Linux Security Advisory GLSA 200506-02 https://security.gentoo.org/ Severity: Normal Title: Mailutils: SQL Injection Date: June 06, 2005 Bugs: #94824 ID: 200506-02

Synopsis ======= GNU Mailutils is vulnerable to SQL command injection attacks.
Background ========= GNU Mailutils is a collection of mail-related utilities.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-mail/mailutils < 0.6-r1 >= 0.6-r1
========== When GNU Mailutils is built with the "mysql" or "postgres" USE flag, the sql_escape_string function of the authentication module fails to properly escape the "\" character, rendering it vulnerable to a SQL command injection.
Impact ==...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround