Summary
The remote host is missing an update to libapache2-mod-auth-pgsql announced via advisory DSA 935-1.
iDEFENSE reports that a format string vulnerability in mod_auth_pgsql, a library used to authenticate web users against a PostgreSQL database, could be used to execute arbitrary code with the privileges of the httpd user.
The old stable distribution (woody) does not contain libapache2-mod-auth-pgsql.
Solution
For the stable distribution (sarge) this problem has been fixed in version 2.0.2b1-5sarge0.
For the unstable distribution (sid) this problem will be fixed shortly.
We recommend that you upgrade your libapache2-mod-auth-pgsql package.
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20935-1
Severity
Classification
-
CVE CVE-2005-3656 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities