Unspecified vulnerability in the SQL logging facility in PAM-MySQL 0.6.x...
Vulnerability Description
Unspecified vulnerability in the SQL logging facility in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors, probably involving the pam_mysql_sql_log function when being used in vsftpd, which does not include the IP address argument to an sprintf call.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2005-4713
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/16564
- http://www.vupen.com/english/advisories/2006/0490
- http://sourceforge.net/tracker/index.php?func=detail&aid=1256243&group_id=5741&atid=305741
- http://secunia.com/advisories/18598
- http://sourceforge.net/forum/forum.php?forum_id=499394
- http://www.gentoo.org/security/en/glsa/glsa-200606-18.xml
- http://secunia.com/advisories/20690
Affected Vendor
pam mysql
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.