Bug 480238 (CVE-2008-2384)

Summary: CVE-2008-2384 mod_auth_mysql: character encoding SQL injection flaw
Product: [Other] Security Response Reporter: Josh Bressers <bressers>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: jlieskov, jorton, kreilly, kseifried, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-09-30 21:18:26 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 480612, 480613, 480614, 663414, 663617, 663618, 795940    
Bug Blocks:    

Description Josh Bressers 2009-01-15 20:39:48 UTC
Martin Joey Schulze discovered a flaw in the way mod_auth_mysql handles certain multibyte character encodings.

If mod_auth_mysql is configured to use use a multibyte character set that allows the backslash '\' character as part of the character encodings, it is possible to inject arbitrary SQL commands to the MySQL database server.

Comment 7 Jan Lieskovsky 2010-12-15 18:06:38 UTC
Created mod_auth_mysql tracking bugs for this issue

Affects: fedora-all [bug 663414]

Comment 10 errata-xmlrpc 2010-12-21 17:42:03 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2010:1002 https://rhn.redhat.com/errata/RHSA-2010-1002.html