Multiple format string vulnerabilities in logging functions in mod_auth_pgsql before 2.0.3, when used for user authentication against a PostgreSQL database, allows remote unauthenticated attackers to execute arbitrary code, as demonstrated via the username.
| Software | From | Fixed in |
|---|---|---|
| guiseppe_tanzilli_and_matthias_eckermann / mod_auth_pgsql | 0.9.5 | 0.9.5.x |
| guiseppe_tanzilli_and_matthias_eckermann / mod_auth_pgsql | 0.9.6 | 0.9.6.x |
| guiseppe_tanzilli_and_matthias_eckermann / mod_auth_pgsql | - | 2.0.3.x |