SQLgrey Postfix Greylisting Service Unspecified SQL Injection Vulnerability
BID:11898
Info
SQLgrey Postfix Greylisting Service Unspecified SQL Injection Vulnerability
| Bugtraq ID: | 11898 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 13 2004 12:00AM |
| Updated: | Dec 13 2004 12:00AM |
| Credit: | This vulnerability was reported by the vendor. |
| Vulnerable: |
SQLgrey SQLgrey Postfix Greylisting Service 1.3 .0 SQLgrey SQLgrey Postfix Greylisting Service 1.2 .0 SQLgrey SQLgrey Postfix Greylisting Service 1.1.3 SQLgrey SQLgrey Postfix Greylisting Service 1.1.1 |
| Not Vulnerable: |
SQLgrey SQLgrey Postfix Greylisting Service 1.4 .0 |
Discussion
SQLgrey Postfix Greylisting Service Unspecified SQL Injection Vulnerability
SQLgrey Postfix Greylisting Service is prone to an unspecified SQL injection vulnerability. This issue is reportedly due to insufficient sanitization of SQL syntax from fields in email processed by the software.
The issue could be exploited to influence SQL queries, potentially allowing for compromise of the software or other attacks that impact database security.
This issue was reportedly missed by the vendor when they fixed the issue described in BID 11633.
SQLgrey Postfix Greylisting Service is prone to an unspecified SQL injection vulnerability. This issue is reportedly due to insufficient sanitization of SQL syntax from fields in email processed by the software.
The issue could be exploited to influence SQL queries, potentially allowing for compromise of the software or other attacks that impact database security.
This issue was reportedly missed by the vendor when they fixed the issue described in BID 11633.
Exploit / POC
SQLgrey Postfix Greylisting Service Unspecified SQL Injection Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
SQLgrey Postfix Greylisting Service Unspecified SQL Injection Vulnerability
Solution:
The vendor has released version 1.4.0 of the affected package to resolve this issue:
SQLgrey SQLgrey Postfix Greylisting Service 1.1.1
SQLgrey SQLgrey Postfix Greylisting Service 1.1.3
SQLgrey SQLgrey Postfix Greylisting Service 1.2 .0
SQLgrey SQLgrey Postfix Greylisting Service 1.3 .0
Solution:
The vendor has released version 1.4.0 of the affected package to resolve this issue:
SQLgrey SQLgrey Postfix Greylisting Service 1.1.1
-
SQLgrey sqlgrey-1.4.0.tar.bz2
http://prdownloads.sourceforge.net/sqlgrey/sqlgrey-1.4.0.tar.bz2?downl oad
SQLgrey SQLgrey Postfix Greylisting Service 1.1.3
-
SQLgrey sqlgrey-1.4.0.tar.bz2
http://prdownloads.sourceforge.net/sqlgrey/sqlgrey-1.4.0.tar.bz2?downl oad
SQLgrey SQLgrey Postfix Greylisting Service 1.2 .0
-
SQLgrey sqlgrey-1.4.0.tar.bz2
http://prdownloads.sourceforge.net/sqlgrey/sqlgrey-1.4.0.tar.bz2?downl oad
SQLgrey SQLgrey Postfix Greylisting Service 1.3 .0
-
SQLgrey sqlgrey-1.4.0.tar.bz2
http://prdownloads.sourceforge.net/sqlgrey/sqlgrey-1.4.0.tar.bz2?downl oad
References
SQLgrey Postfix Greylisting Service Unspecified SQL Injection Vulnerability
References:
References:
- SQLgrey Homepage (SQLgrey)
- SQLgrey Postfix Greylisting Service 1.4.0 Changes (SQLgrey)