VDB
CVE-2005-3656
CVE-2005-3656
PUBLISHED
CVSS 10 CRITICAL
Multiple format string vulnerabilities in logging functions in mod_auth_pgsql before 2.0.3, when used for user authentication against a PostgreSQL database, allows remote unauthenticated attackers to execute arbitrary code, as demonstrated via the username.
EPSS 8.90% · 95.1th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
8.90%
95.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| guiseppe_tanzilli_and_matthias_eckermann | mod_auth_pgsql | 0.9.5, 0, 0.9.6 |
| n/a | n/a | n/a |
Timeline
- CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
- Nov 1, 2023 EPSS Score
References
- http://secunia.com/advisories/18397 patch
- http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00016.html url
- 18350 third-party-advisory
- MDKSA-2006:009 vendor-advisory
- http://www.giuseppetanzilli.it/mod_auth_pgsql2/ url
- 20060101-01-U vendor-advisory
- oval:org.mitre.oval:def:10600 vdb
- http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00015.html url
- 18348 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2005-3656 advisory
- https://usn.ubuntu.com/239-1 url
- http://secunia.com/advisories/18321 url
- http://secunia.com/advisories/18347 url
- http://secunia.com/advisories/18403 url
- http://secunia.com/advisories/18463 url
- http://www.giuseppetanzilli.it/mod%5Fauth%5Fpgsql2 url
- http://www.idefense.com/intelligence/vulnerabilities/display.php?id=367 url
- http://www.securityfocus.com/bid/16153 url
- http://www.trustix.org/errata/2006/0002 url
- http://www.vupen.com/english/advisories/2006/0070 url
…and 8 more