Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-0688

Опубликовано: 15 мая 2008
Источник: redhat
CVSS2: 6.4

Описание

Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via strings that are used as input to the sasl_encode64 function in lib/saslutil.c.

Отчет

The upstream fix for this issue is not backwards compatible and introduces an ABI change not allowed in Red Hat Enterprise Linux. Therefore, there is no plan to address this problem directly in cyrus-sasl packages. All applications shipped in Red Hat Enterprise Linux and using affected sasl_encode64() function were investigated and patched if their use of the function could have security consequences. See following bug report for further details: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-0688#c20

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=487251cyrus-sasl: sasl_encode64() does not reliably null-terminate its output

6.4 Medium

CVSS2

Связанные уязвимости

ubuntu
около 16 лет назад

Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via strings that are used as input to the sasl_encode64 function in lib/saslutil.c.

nvd
около 16 лет назад

Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via strings that are used as input to the sasl_encode64 function in lib/saslutil.c.

debian
около 16 лет назад

Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 ...

github
около 3 лет назад

Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via strings that are used as input to the sasl_encode64 function in lib/saslutil.c.

oracle-oval
около 16 лет назад

ELSA-2009-1116: cyrus-imapd security update (IMPORTANT)

6.4 Medium

CVSS2