CVE-2005-3656

Description

From CVE.org

Multiple format string vulnerabilities in logging functions in mod_auth_pgsql before 2.0.3, when used for user authentication against a PostgreSQL database, allows remote unauthenticated attackers to execute arbitrary code, as demonstrated via the username.

Acknowledgements

Red Hat would like to thank iDefense for reporting this issue.

Frequently Asked Questions

Want to get errata notifications? Sign up here.