VDB
CVE-2005-3656
CVE-2005-3656
PUBLISHED
CVSS 10 CRITICAL
Multiple format string vulnerabilities in logging functions in mod_auth_pgsql before 2.0.3, when used for user authentication against a PostgreSQL database, allows remote unauthenticated attackers to execute arbitrary code, as demonstrated via the username.
EPSS 49.58% · 97.9th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
49.58%
97.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| guiseppe_tanzilli_and_matthias_eckermann | mod_auth_pgsql | 0.9.5, 0, 0.9.6 |
| n/a | n/a | n/a |
Timeline
- CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- http://secunia.com/advisories/18397 patch
- http://secunia.com/advisories/18403 patch
- http://secunia.com/advisories/18463 patch
- GLSA-200601-05 vendor-advisory
- 18321 third-party-advisory
- http://www.giuseppetanzilli.it/mod_auth_pgsql2/ url
- http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00016.html url
- 16153 vdb
- USN-239-1 vendor-advisory
- 18347 third-party-advisory
- 18304 third-party-advisory
- 2006-0002 vendor-advisory
- 18350 third-party-advisory
- ADV-2006-0070 vdb
- 20060101-01-U vendor-advisory
- RHSA-2006:0164 vendor-advisory
- oval:org.mitre.oval:def:10600 vdb
- 18517 third-party-advisory
- http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00015.html url
- 1015446 vdb
…and 8 more