UBUNTU-CVE-2016-8640

Source
https://ubuntu.com/security/CVE-2016-8640
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2016/UBUNTU-CVE-2016-8640.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2016-8640
Related
Published
2018-08-01T18:29:00Z
Modified
2025-01-13T10:21:16Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

A SQL injection vulnerability in pycsw all versions before 2.0.2, 1.10.5 and 1.8.6 that leads to read and extract of any data from any table in the pycsw database that the database user has access to. Also on PostgreSQL (at least) it is possible to perform updates/inserts/deletes and database modifications to any table the database user has access to.

References

Affected packages

Ubuntu:Pro:16.04:LTS / pycsw

Package

Name
pycsw
Purl
pkg:deb/ubuntu/pycsw@1.10.1+dfsg-2?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.10.1+dfsg-2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}