Package: libsqlite3-ruby1.8
Version: 1.2.1-1
Severity: important

Hi,

sqlite3 provides a function sqlite3_mprintf to escape SQL characters
in a given string. This seems to not be implemented in the ruby
frontend.

This is an *extremely* important and security relevant function.

regards


-- System Information:
Debian Release: lenny/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.22-2-k7 (SMP w/2 CPU cores)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages libsqlite3-ruby1.8 depends on:
ii  libc6                        2.7-3       GNU C Library: Shared libraries
ii  libruby1.8                   1.8.6.111-2 Libraries necessary to run Ruby 1.
ii  libsqlite3-0                 3.4.2-2     SQLite 3 shared library

libsqlite3-ruby1.8 recommends no packages.

-- no debconf information



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to