missing input sanitising

Primoz Bratanic discovered a bug in libpam-pgsql, a PAM module to authenticate using a PostgreSQL database. The library does not escape all user-supplied data that are sent to the database. An attacker could exploit this bug to insert SQL statements.

For the stable distribution (woody) this problem has been fixed in version 0.5.2-3woody2.

For the unstable distribution (sid) this problem has been fixed in version 0.5.2-7.1.

We recommend that you upgrade your libpam-pgsql package.

