Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hmpx-mhc7-wxwr

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.

Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.

EPSS

Процентиль: 93%
0.09976
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-131

Связанные уязвимости

redhat
больше 22 лет назад

Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.

CVSS3: 9.8
nvd
больше 22 лет назад

Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.

CVSS3: 9.8
debian
больше 22 лет назад

Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allo ...

EPSS

Процентиль: 93%
0.09976
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-131