Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Scientific Linux 5.x: 2009-02-11 Moderate: mod_auth_mysql Remote Attack

Scientific Large Esm H446
Moderate: mod_auth_mysql security update
Date: Wed, 11 Feb 2009 14:52:28 -0600
Reply-To: Troy Dawson 
Sender: Security Errata for Scientific Linux
 
From: Troy Dawson 
Subject: Security ERRATA Moderate: mod_auth_mysql on SL5.x i386/x86_64
Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it."
 

Synopsis:	Moderate: mod_auth_mysql security update
Issue date:	2009-02-11
CVE Names:	CVE-2008-2384

A flaw was found in the way mod_auth_mysql escaped certain
multibyte-encoded strings. If mod_auth_mysql was configured to use a
multibyte character set that allowed a backslash '\' as part of the
character encodings, a remote attacker could inject arbitrary SQL
commands into a login request. (CVE-2008-2384)

Note: This flaw only affected non-default installations where
AuthMySQLCharacterSet is configured to use one of the affected multibyte
character sets. Installations that did not use the AuthMySQLCharacterSet
configuration option were not vulnerable to this flaw.

After installing the update, the httpd daemon must be restarted for the
fix to take effect.

SL 5.x

 SRPMS:
mod_auth_mysql-3.0.0-3.2.el5_3.src.rpm
 i386:
mod_auth_mysql-3.0.0-3.2.el5_3.i386.rpm
 x86_64:
mod_auth_mysql-3.0.0-3.2.el5_3.x86_64.rpm

-Connie Sieh
-Troy Dawson