Summary
The remote host is missing an update to pam-pgsql
announced via advisory DSA 469-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20469-1
Insight
Primoz Bratanic discovered a bug in libpam-psgl, a PAM module to authenticate using a PostgreSQL database. The library does not escape all user-supplied data that are sent to the database. An attacker could exploit this bug to insert SQL statements.
For the stable distribution (woody) this problem has been fixed in version 0.5.2-3woody2.
For the unstable distribution (sid) this problem has been fixed in version 0.5.2-7.1.
We recommend that you upgrade your libpam-pgsql package.
Severity
Classification
-
CVE CVE-2004-0366 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities