CVE-2005-4713
EPSS 1.9%
Description
Unspecified vulnerability in the SQL logging facility in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors, probably involving the pam_mysql_sql_log function when being used in vsftpd, which does not include the IP address argument to an sprintf call.
How to fix CVE-2005-4713
To remediate CVE-2005-4713, upgrade the affected package to a fixed version below.
- Debian/pam-mysql—upgrade to 0.6.2-1 or later
Is CVE-2005-4713 being exploited?
Low — EPSS is 1.9%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.6.2-1