Likewise Open lsassd Service SQL Injection Vulnerability
BID:48816
Info
Likewise Open lsassd Service SQL Injection Vulnerability
| Bugtraq ID: | 48816 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-2467 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2011 12:00AM |
| Updated: | Jul 22 2011 05:30PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Likewise Software Likewise Open 6.1 Likewise Software Likewise Open 6.0 Likewise Software Likewise Open 5.4 Likewise Software Likewise Enterprise 6.0 |
| Not Vulnerable: | |
Discussion
Likewise Open lsassd Service SQL Injection Vulnerability
Likewise Open is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Likewise Open is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Exploit / POC
Likewise Open lsassd Service SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Likewise Open lsassd Service SQL Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Likewise Open lsassd Service SQL Injection Vulnerability
References:
References:
- Vendor Homepage (Likewise Software)
- Likewise Security Advisory LWSA-2011-002 (Likewise Software)