CVE-2008-2384

Publication date 22 January 2009

Last updated 24 July 2024


Ubuntu priority

Description

SQL injection vulnerability in mod_auth_mysql.c in the mod-auth-mysql (aka libapache2-mod-auth-mysql) module for the Apache HTTP Server 2.x, when configured to use a multibyte character set that allows a \ (backslash) as part of the character encoding, allows remote attackers to execute arbitrary SQL commands via unspecified inputs in a login request.

Read the notes from the security team

Status

Package Ubuntu Release Status
libapache-mod-auth-mysql 8.10 intrepid Not in release
8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
6.06 LTS dapper
Not affected
mod-auth-mysql 8.10 intrepid
Not affected
8.04 LTS hardy Not in release
7.10 gutsy Not in release
6.06 LTS dapper Not in release

Notes


mdeslaur

Specifying an encoding was introduced by the 012-charset.dpatch patch in 4.3.9-10. Since we don't support specifying an encoding mysql won't decode the username and injection is not possible.

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
mod-auth-mysql

Access our resources on patching vulnerabilities