DEBIAN-CVE-2016-8640

Source
https://security-tracker.debian.org/tracker/CVE-2016-8640
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2016-8640.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2016-8640
Upstream
Published
2018-08-01T18:29:00.220Z
Modified
2025-11-14T04:01:35.117442Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

A SQL injection vulnerability in pycsw all versions before 2.0.2, 1.10.5 and 1.8.6 that leads to read and extract of any data from any table in the pycsw database that the database user has access to. Also on PostgreSQL (at least) it is possible to perform updates/inserts/deletes and database modifications to any table the database user has access to.

References

Affected packages

Debian:11 / pycsw

Package

Name
pycsw
Purl
pkg:deb/debian/pycsw?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.2+dfsg-1

Affected versions

1.*

1.10.0+dfsg-1
1.10.1+dfsg-1
1.10.1+dfsg-2
1.10.4+dfsg-1
1.10.4+dfsg-2

2.*

2.0.0~rc1+dfsg-1~exp1
2.0.0~rc1+dfsg-1~exp2
2.0.0+dfsg-1~exp1
2.0.0+dfsg-1~exp2
2.0.0+dfsg-1~exp3
2.0.0+dfsg-1
2.0.1+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2016-8640.json"

Debian:12 / pycsw

Package

Name
pycsw
Purl
pkg:deb/debian/pycsw?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.2+dfsg-1

Affected versions

1.*

1.10.0+dfsg-1
1.10.1+dfsg-1
1.10.1+dfsg-2
1.10.4+dfsg-1
1.10.4+dfsg-2

2.*

2.0.0~rc1+dfsg-1~exp1
2.0.0~rc1+dfsg-1~exp2
2.0.0+dfsg-1~exp1
2.0.0+dfsg-1~exp2
2.0.0+dfsg-1~exp3
2.0.0+dfsg-1
2.0.1+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2016-8640.json"

Debian:13 / pycsw

Package

Name
pycsw
Purl
pkg:deb/debian/pycsw?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.2+dfsg-1

Affected versions

1.*

1.10.0+dfsg-1
1.10.1+dfsg-1
1.10.1+dfsg-2
1.10.4+dfsg-1
1.10.4+dfsg-2

2.*

2.0.0~rc1+dfsg-1~exp1
2.0.0~rc1+dfsg-1~exp2
2.0.0+dfsg-1~exp1
2.0.0+dfsg-1~exp2
2.0.0+dfsg-1~exp3
2.0.0+dfsg-1
2.0.1+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2016-8640.json"

Debian:14 / pycsw

Package

Name
pycsw
Purl
pkg:deb/debian/pycsw?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.2+dfsg-1

Affected versions

1.*

1.10.0+dfsg-1
1.10.1+dfsg-1
1.10.1+dfsg-2
1.10.4+dfsg-1
1.10.4+dfsg-2

2.*

2.0.0~rc1+dfsg-1~exp1
2.0.0~rc1+dfsg-1~exp2
2.0.0+dfsg-1~exp1
2.0.0+dfsg-1~exp2
2.0.0+dfsg-1~exp3
2.0.0+dfsg-1
2.0.1+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2016-8640.json"