Bug#307796: xtradius: sql injection in authmysql

2005-05-13 Thread Russ Allbery
severity 307796 normal thanks > Package: xtradius > Severity: grave > Tags: security > Justification: user security hole > > There is no user input verification whatsoever. In > /contrib/authmysql/authmysql.c username supplied by user is fed directly > to database. Er, unless I'm missing somethi

Processed: Re: Bug#307796: xtradius: sql injection in authmysql

2005-05-13 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > severity 307796 normal Bug#307796: xtradius: sql injection in authmysql Severity set to `normal'. > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system administrator (administrator,

Bug#307796: xtradius: sql injection in authmysql

2005-05-05 Thread Primoz Bratanic
Package: xtradius Severity: grave Tags: security Justification: user security hole -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 There is no user input verification whatsoever. In /contrib/authmysql/authmysql.c username supplied by user is fed directly to database. Primoz Bratanic - -- Syst