Vulnerability Description
The sql_escape_string function in auth/sql.c for the mailutils SQL authentication module does not properly quote the "\" (backslash) character, which is used as an escape character and makes the module vulnerable to SQL injection attacks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Mailutils | 1.0.6.1.1 |
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=308031PatchVendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200506-02.xml
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=308031PatchVendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200506-02.xml
FAQ
What is CVE-2005-1824?
CVE-2005-1824 is a vulnerability with a CVSS score of 7.5 (HIGH). The sql_escape_string function in auth/sql.c for the mailutils SQL authentication module does not properly quote the "\" (backslash) character, which is used as an escape character and makes the modul...
How severe is CVE-2005-1824?
CVE-2005-1824 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-1824?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Mailutils.