Debian Security Advisory
DSA-2177-1 pywebdav -- SQL injection
- Date Reported:
- 02 Mar 2011
- Affected Packages:
- pywebdav
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2011-0432.
- More information:
-
It was discovered that PyWebDAV, a WebDAV server implementation, contains several SQL injection vulnerabilities in the processing of user credentials.
The oldstable distribution (lenny) does not contain a python-webdav package.
For the stable distribution (squeeze), this problem has been fixed in version 0.9.4-1+squeeze1.
For the testing distribution (wheezy) and the unstable distribution (sid), this problem has been fixed in version 0.9.4-3.
We recommend that you upgrade your python-webdav packages.