php-auth: [CVE-2006-0868] Multiple unspecified injection vulnerabilities

Related Vulnerabilities: CVE-2006-0868  

Debian Bug report logs - #354474
php-auth: [CVE-2006-0868] Multiple unspecified injection vulnerabilities

version graph

Reported by: Stefan Fritsch <sf@sfritsch.de>

Date: Sun, 26 Feb 2006 16:03:05 UTC

Severity: grave

Tags: security

Fixed in version php-auth/1.2.4-0.1

Done: "Steinar H. Gunderson" <sgunderson@bigfoot.com>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Debian Security Team <team@security.debian.org>, Chris Anderson <chris@nullcode.org>:
Bug#354474; Package php-auth. (full text, mbox, link).


Acknowledgement sent to Stefan Fritsch <sf@sfritsch.de>:
New Bug report received and forwarded. Copy sent to Debian Security Team <team@security.debian.org>, Chris Anderson <chris@nullcode.org>. (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Stefan Fritsch <sf@sfritsch.de>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: php-auth: [CVE-2006-0868] Multiple unspecified injection vulnerabilities
Date: Sun, 26 Feb 2006 16:58:29 +0100
Package: php-auth
Severity: grave
Tags: security
Justification: user security hole

Cite:
Multiple unspecified injection vulnerabilities in unspecified Auth
Container back ends for PEAR::Auth before 1.2.4, and 1.3.x before
1.3.0r4, allow remote attackers to "falsify authentication
credentials," related to the "underlying storage containers."

See also:
http://www.securityfocus.com/archive/1/archive/1/425796/100/0/threaded

Please mention the CVE number in the changelog



Tags added: fixed Request was from sesse@debian.org (Steinar H. Gunderson) to control@bugs.debian.org. (full text, mbox, link).


Tags removed: fixed Request was from "Steinar H. Gunderson" <sgunderson@bigfoot.com> to control@bugs.debian.org. (full text, mbox, link).


Bug marked as fixed in version 1.2.4-0.1, send any further explanations to Stefan Fritsch <sf@sfritsch.de> Request was from "Steinar H. Gunderson" <sgunderson@bigfoot.com> to control@bugs.debian.org. (full text, mbox, link).


Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Tue, 26 Jun 2007 13:43:56 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 12:59:09 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.