CVE-2006-0150

NameCVE-2006-0150
DescriptionMultiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-952-1
Debian Bugs347416

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libapache-auth-ldapsourcewoody1.6.0-3.1DSA-952-1
libapache-auth-ldapsourcesarge1.6.0-8.1DSA-952-1
libapache-auth-ldapsource(unstable)(unfixed)347416

Search for package or bug name: Reporting problems