DSA-2279-1 libapache2-mod-authnz-external -- SQL injection

Related Vulnerabilities: CVE-2011-2688  

It was discovered that libapache2-mod-authnz-external, an apache authentication module, is prone to an SQL injection via the $user parameter. For the stable distribution (squeeze), this problem has been fixed in version 3.2.4-2+squeeze1. The oldstable distribution (lenny) does not contain libapache2-mod-authnz-external. For the testing distribution (wheezy), this problem will be fixed soon. For the unstable distribution (sid), this problem has been fixed in version 3.2.4-2.1. We recommend that you upgrade your libapache2-mod-authnz-external packages.

Debian Security Advisory

DSA-2279-1 libapache2-mod-authnz-external -- SQL injection

Date Reported:
19 Jul 2011
Affected Packages:
libapache2-mod-authnz-external
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 633637.
In Mitre's CVE dictionary: CVE-2011-2688.
More information:

It was discovered that libapache2-mod-authnz-external, an apache authentication module, is prone to an SQL injection via the $user parameter.

For the stable distribution (squeeze), this problem has been fixed in version 3.2.4-2+squeeze1.

The oldstable distribution (lenny) does not contain libapache2-mod-authnz-external.

For the testing distribution (wheezy), this problem will be fixed soon.

For the unstable distribution (sid), this problem has been fixed in version 3.2.4-2.1.

We recommend that you upgrade your libapache2-mod-authnz-external packages.