
September 1st, 2001, 05:52 AM
|
|
Contributing User
|
|
Join Date: Jan 2001
Posts: 5
Time spent in forums: < 1 sec
Reputation Power: 0
|
|
|
Security vulnerability found in several mod_auth_*
RUS-CERT has discovered a vulnerability that affects several third-party Apache authentication modules that use SQL databases to store authentication information. An external attacker can make use of this vulnerability to obtain arbitrary data from your server. The modules known to be affected include:
* AuthPG
* mod_auth_mysql
* mod_auth_oracle
* mod_auth_pgsql
* mod_auth_pgsql_sys
If you are using one of these modules, or any other module to authenticate against a SQL database read the full advisory and update your module.
http://cert.uni-stuttgart.de/advisories/apache_auth.php
|