The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes.
| Software | From | Fixed in |
|---|---|---|
| pam_mysql / pam_mysql | 0.1 | 0.1.x |
| pam_mysql / pam_mysql | 0.4 | 0.4.x |
| pam_mysql / pam_mysql | 0.3 | 0.3.x |
| pam_mysql / pam_mysql | 0.2 | 0.2.x |