CVE-2005-3656

Publication date 31 December 2005

Last updated 17 July 2025


Ubuntu priority

Multiple format string vulnerabilities in logging functions in mod_auth_pgsql before 2.0.3, when used for user authentication against a PostgreSQL database, allows remote unauthenticated attackers to execute arbitrary code, as demonstrated via the username.

Status

Package Ubuntu Release Status
libapache2-mod-auth-pgsql 7.04 feisty
Fixed 2.0.3-2
6.10 edgy
Fixed 2.0.3-2
6.06 LTS dapper
Fixed 2.0.3-2

References

Related Ubuntu Security Notices (USN)

    • USN-239-1
    • libapache2-mod-auth-pgsql vulnerability
    • 9 January 2006

Other references