CVE-2008-2667
published 2008-07-07CVE-2008-2667: SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0.60.6 on SUSE openSUSE 10.3 and 11.0, and other platforms, when…
PriorityP433medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
1.53%
72.2th percentile
SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0.60.6 on SUSE openSUSE 10.3 and 11.0, and other platforms, when MySQL and a non-Latin character set are used, allows remote attackers to execute arbitrary SQL commands via the username and unspecified other vectors.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| courier-mta | courtier-authlib | — | — |
| courier-mta | courtier-authlib | — | — |
| courier-mta | courtier-authlib | — | — |
| courier-mta | courtier-authlib | — | — |
| courier-mta | courtier-authlib | — | — |
| courier-mta | courtier-authlib | — | — |
| courier-mta | courtier-authlib | — | — |
| courier-mta | courtier-authlib | — | — |
| courier-mta | courtier-authlib | — | — |
| courier-mta | courtier-authlib | — | — |
| courier-mta | courtier-authlib | — | — |
| courier-mta | courtier-authlib | — | — |
| courier-mta | courtier-authlib | — | — |
| courier-mta | courtier-authlib | — | — |
| courier-mta | courtier-authlib | — | — |
| courier-mta | courtier-authlib | — | — |
| courier-mta | courtier-authlib | — | — |
| debian | courier-authlib | < courier-authlib 0.60.1-2.1 (bookworm) | courier-authlib 0.60.1-2.1 (bookworm) |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv5.1MEDIUM
vendor_debian5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3r5f-vjfp-r32c: SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0
ghsa_unreviewed·2022-05-01
CVE-2008-2667 [MEDIUM] CWE-89 GHSA-3r5f-vjfp-r32c: SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0
SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0.60.6 on SUSE openSUSE 10.3 and 11.0, and other platforms, when MySQL and a non-Latin character set are used, allows remote attackers to execute arbitrary SQL commands via the username and unspecified other vectors.
OSV
CVE-2008-2667: SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0
osv·2008-07-07·CVSS 5.1
CVE-2008-2667 [MEDIUM] CVE-2008-2667: SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0
SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0.60.6 on SUSE openSUSE 10.3 and 11.0, and other platforms, when MySQL and a non-Latin character set are used, allows remote attackers to execute arbitrary SQL commands via the username and unspecified other vectors.
Debian
CVE-2008-2667: courier-authlib - SQL injection vulnerability in the Courier Authentication Library (aka courier-a...
vendor_debian·2008·CVSS 5.1
CVE-2008-2667 [MEDIUM] CVE-2008-2667: courier-authlib - SQL injection vulnerability in the Courier Authentication Library (aka courier-a...
SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0.60.6 on SUSE openSUSE 10.3 and 11.0, and other platforms, when MySQL and a non-Latin character set are used, allows remote attackers to execute arbitrary SQL commands via the username and unspecified other vectors.
Scope: local
bookworm: resolved (fixed in 0.60.1-2.1)
bullseye: resolved (fixed in 0.60.1-2.1)
forky: resolved (fixed in 0.60.1-2.1)
sid: resolved (fixed in 0.60.1-2.1)
trixie: resolved (fixed in 0.60.1-2.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bugs.gentoo.org/show_bug.cgi?id=225407http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.htmlhttp://secunia.com/advisories/30591http://secunia.com/advisories/30967http://security.gentoo.org/glsa/glsa-200809-05.xmlhttp://www.courier-mta.org/authlib/changelog.htmlhttp://www.mail-archive.com/courier-users%40lists.sourceforge.net/msg31362.htmlhttp://www.nabble.com/courier-authlib-0.60.6-released-td17720739.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/43628http://bugs.gentoo.org/show_bug.cgi?id=225407http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.htmlhttp://secunia.com/advisories/30591http://secunia.com/advisories/30967http://security.gentoo.org/glsa/glsa-200809-05.xmlhttp://www.courier-mta.org/authlib/changelog.htmlhttp://www.mail-archive.com/courier-users%40lists.sourceforge.net/msg31362.htmlhttp://www.nabble.com/courier-authlib-0.60.6-released-td17720739.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/43628
2008-07-07
Published