[<prev] [next>] [day] [month] [year] [list]
Message-ID: <CAPKNUtfvmZOLjmO5eM48TXk3R5RJ633Fp=6pVE9k2pF3K5sfhQ@mail.gmail.com>
Date: Wed, 24 Aug 2011 07:45:23 -0700
From: Chris Travers <chris@...atrontech.com>
To: bugtraq@...urityfocus.com
Subject: SQL-Ledger patch update for SQL injection
Hi all;
We have been informed that SQL-Ledger 2.8.34 has in fact been released
patching the security hole previously reported in LedgerSMB 1.2.24 and
Lower. This is an SQL injection issue.
I haven't been been able to find a CVE listing for this yet. Secunia
has assigned this the id of SA45649 for LedgerSMB. I expect to send a
full disclosure email discussing the vulnerability in a week.
Best Wishes,
Chris Travers
Powered by blists - more mailing lists