Summary
The remote host is missing an update to apache-mod_auth_mysql announced via advisory MDVSA-2009:189-1.
Solution
To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.
https://secure1.securityspace.com/smysecure/catid.html?in=MDVSA-2009:189-1
Insight
A vulnerability has been found and corrected in mod_auth_mysql:
SQL injection vulnerability in mod_auth_mysql.c in the mod-auth-mysql (aka libapache2-mod-auth-mysql) module for the Apache HTTP Server 2.x allows remote attackers to execute arbitrary SQL commands via multibyte character encodings for unspecified input (CVE-2008-2384).
This update provides fixes for this vulnerability.
Update:
Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers.
Affected: 2008.0
Severity
Classification
-
CVE CVE-2008-2384 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities