Package: php-auth
Severity: grave
Tags: security
Justification: user security hole

Cite:
Multiple unspecified injection vulnerabilities in unspecified Auth
Container back ends for PEAR::Auth before 1.2.4, and 1.3.x before
1.3.0r4, allow remote attackers to "falsify authentication
credentials," related to the "underlying storage containers."

See also:
http://www.securityfocus.com/archive/1/archive/1/425796/100/0/threaded

Please mention the CVE number in the changelog


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to