SQLgrey Postfix Greylisting Service SQL Injection Vulnerability
BID:11633
Info
SQLgrey Postfix Greylisting Service SQL Injection Vulnerability
| Bugtraq ID: | 11633 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 08 2004 12:00AM |
| Updated: | Nov 08 2004 12:00AM |
| Credit: | This issue was announced by the vendor. |
| Vulnerable: |
SQLgrey SQLgrey Postfix Greylisting Service 1.1.3 SQLgrey SQLgrey Postfix Greylisting Service 1.1.1 |
| Not Vulnerable: |
SQLgrey SQLgrey Postfix Greylisting Service 1.2 .0 |
Discussion
SQLgrey Postfix Greylisting Service SQL Injection Vulnerability
SQLgrey Postfix Greylisting Service is prone to an SQL injection vulnerability. This issue is reportedly due to insufficient sanitization of SQL syntax from fields in email processed by the software.
The issue could be exploited to influence SQL queries, potentially allowing for compromise of the software or other attacks that impact database security.
SQLgrey Postfix Greylisting Service is prone to an SQL injection vulnerability. This issue is reportedly due to insufficient sanitization of SQL syntax from fields in email processed by the software.
The issue could be exploited to influence SQL queries, potentially allowing for compromise of the software or other attacks that impact database security.
Exploit / POC
SQLgrey Postfix Greylisting Service SQL Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
SQLgrey Postfix Greylisting Service SQL Injection Vulnerability
Solution:
This issue is addressed in version 1.2.0.
Trustix Linux has released an advisory (TSLSA-2004-0058) along with fixes dealing with this and other issues. Please see the referenced advisory for more information.
SQLgrey SQLgrey Postfix Greylisting Service 1.1.1
SQLgrey SQLgrey Postfix Greylisting Service 1.1.3
Solution:
This issue is addressed in version 1.2.0.
Trustix Linux has released an advisory (TSLSA-2004-0058) along with fixes dealing with this and other issues. Please see the referenced advisory for more information.
SQLgrey SQLgrey Postfix Greylisting Service 1.1.1
-
SQLgrey SQLgrey Postfix Greylisting Service 1.2.0
http://sourceforge.net/project/showfiles.php?group_id=113566
SQLgrey SQLgrey Postfix Greylisting Service 1.1.3
-
SQLgrey SQLgrey Postfix Greylisting Service 1.2.0
http://sourceforge.net/project/showfiles.php?group_id=113566
References
SQLgrey Postfix Greylisting Service SQL Injection Vulnerability
References:
References:
- SQLgrey Homepage (SQLgrey)
- SQLgrey Postfix Greylisting Service 1.2.0 Changes (SQLgrey)