Unrated severityNVD Advisory· Published Dec 31, 2005· Updated Apr 16, 2026
CVE-2005-3656
CVE-2005-3656
Description
Multiple format string vulnerabilities in logging functions in mod_auth_pgsql before 2.0.3, when used for user authentication against a PostgreSQL database, allows remote unauthenticated attackers to execute arbitrary code, as demonstrated via the username.
Affected products
3cpe:2.3:a:guiseppe_tanzilli_and_matthias_eckermann:mod_auth_pgsql:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:guiseppe_tanzilli_and_matthias_eckermann:mod_auth_pgsql:*:*:*:*:*:*:*:*range: <=2.0.3
- cpe:2.3:a:guiseppe_tanzilli_and_matthias_eckermann:mod_auth_pgsql:0.9.5:*:*:*:*:*:*:*
- cpe:2.3:a:guiseppe_tanzilli_and_matthias_eckermann:mod_auth_pgsql:0.9.6:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
24- patches.sgi.com/support/free/security/advisories/20060101-01-UnvdPatch
- secunia.com/advisories/18304nvdPatchVendor Advisory
- secunia.com/advisories/18321nvdPatchVendor Advisory
- secunia.com/advisories/18347nvdPatchVendor Advisory
- secunia.com/advisories/18348nvdPatchVendor Advisory
- secunia.com/advisories/18350nvdPatchVendor Advisory
- secunia.com/advisories/18397nvdPatchVendor Advisory
- secunia.com/advisories/18403nvdPatchVendor Advisory
- secunia.com/advisories/18463nvdPatchVendor Advisory
- secunia.com/advisories/18517nvdPatchVendor Advisory
- securitytracker.com/idnvdPatch
- www.debian.de/security/2006/dsa-935nvdPatchVendor Advisory
- www.gentoo.org/security/en/glsa/glsa-200601-05.xmlnvdPatchVendor Advisory
- www.idefense.com/intelligence/vulnerabilities/display.phpnvdPatchVendor Advisory
- www.redhat.com/archives/fedora-announce-list/2006-January/msg00015.htmlnvdPatch
- www.redhat.com/archives/fedora-announce-list/2006-January/msg00016.htmlnvdPatch
- www.redhat.com/support/errata/RHSA-2006-0164.htmlnvdPatch
- www.securityfocus.com/bid/16153nvdPatch
- www.trustix.org/errata/2006/0002/nvdPatch
- www.giuseppetanzilli.it/mod_auth_pgsql2/nvd
- www.mandriva.com/security/advisoriesnvd
- www.vupen.com/english/advisories/2006/0070nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10600nvd
- usn.ubuntu.com/239-1/nvd
News mentions
0No linked articles in our index yet.