DEBIAN-CVE-2012-0805

Source
https://security-tracker.debian.org/tracker/CVE-2012-0805
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2012-0805.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2012-0805
Upstream
Published
2012-06-05T22:55:08.077Z
Modified
2025-11-14T03:18:32.361530Z
Summary
[none]
Details

Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset keyword to the select function, or unspecified vectors to the (3) select.limit or (4) select.offset function.

References

Affected packages

Debian:11 / sqlalchemy

Package

Name
sqlalchemy
Purl
pkg:deb/debian/sqlalchemy?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.7-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / sqlalchemy

Package

Name
sqlalchemy
Purl
pkg:deb/debian/sqlalchemy?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.7-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / sqlalchemy

Package

Name
sqlalchemy
Purl
pkg:deb/debian/sqlalchemy?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.7-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / sqlalchemy

Package

Name
sqlalchemy
Purl
pkg:deb/debian/sqlalchemy?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.7-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}