Summary
The remote host is missing an update to teapop
announced via advisory DSA 347-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20347-1
Insight
teapop, a POP-3 server, includes modules for authenticating users against a PostgreSQL or MySQL database. These modules do not properly escape user-supplied strings before using them in SQL queries. This vulnerability could be exploited to execute arbitrary SQL under the privileges of the database user as which teapop has authenticated.
For the stable distribution (woody) this problem has been fixed in version 0.3.4-1woody2.
For the unstable distribution (sid) this problem has been fixed in version 0.3.5-2.
We recommend that you update your teapop package.
Severity
Classification
-
CVE CVE-2003-0515 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities