CVE-2006-4041

NameCVE-2006-4041
DescriptionSQL injection vulnerability in Pike before 7.6.86, when using a Postgres database server, allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs382607, 383766

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
pike7.2sourcesarge(unfixed)unimportant382607, 383766
pike7.6sourcesarge(unfixed)unimportant382607, 383766
pike7.6source(unstable)7.6.86-1

Notes

No applications using pike+postgres in Sarge, fix provides
new functions for proper quoting

Search for package or bug name: Reporting problems