Debian Courier-Authlib vulnerabilities

3 known vulnerabilities affecting debian/courier-authlib.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2021-28374HIGHCVSS 7.5fixed in 0.71.1-22021-03-15
CVE-2021-28374 [HIGH] CWE-732 CVE-2021-28374: The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon directory with weak permissions, allowing an attacker to read user information. This may include a cleartext password in some configurations. In general, it includes the user's existence, uid and gids, home and/or Maildir directory,
nvdosvdebian
CVE-2008-2380MEDIUMCVSS 5.1fixed in courier-authlib 0.61.0-1+lenny1 (bookworm)2008
CVE-2008-2380 [MEDIUM] CVE-2008-2380: courier-authlib - SQL injection vulnerability in authpgsqllib.c in Courier-Authlib before 0.62.0, ... SQL injection vulnerability in authpgsqllib.c in Courier-Authlib before 0.62.0, when a non-Latin locale Postgres database is used, allows remote attackers to execute arbitrary SQL commands via query parameters containing apostrophes. Scope: local bookworm: resolved (fixed in 0.61.0-1+lenny1) bullseye: resolved (fixed in 0.61.0-1+lenny1) forky: resolved (fixe
debian
CVE-2008-2667MEDIUMCVSS 5.1fixed in courier-authlib 0.60.1-2.1 (bookworm)2008
CVE-2008-2667 [MEDIUM] CVE-2008-2667: courier-authlib - SQL injection vulnerability in the Courier Authentication Library (aka courier-a... SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0.60.6 on SUSE openSUSE 10.3 and 11.0, and other platforms, when MySQL and a non-Latin character set are used, allows remote attackers to execute arbitrary SQL commands via the username and unspecified other vectors. Scope: local bookworm: resolved (fixed in 0.60.1
debian