Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2002-1347

Опубликовано: 18 дек. 2002
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cyrusimap:cyrus_sasl:*:*:*:*:*:*:*:*
Версия до 2.1.9 (включая)
Конфигурация 2

Одно из

cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
Версия до 10.3.8 (исключая)
cpe:2.3:o:apple:mac_os_x_server:*:*:*:*:*:*:*:*
Версия до 10.3.8 (исключая)

EPSS

Процентиль: 93%
0.09976
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-131

Связанные уязвимости

redhat
больше 22 лет назад

Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.

CVSS3: 9.8
debian
больше 22 лет назад

Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allo ...

CVSS3: 9.8
github
около 3 лет назад

Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.

EPSS

Процентиль: 93%
0.09976
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-131