Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2004-0884

Опубликовано: 27 янв. 2005
Источник: ubuntu
Приоритет: untriaged
EPSS Низкий
CVSS2: 7.2

Описание

The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASL_PATH to point to malicious programs.

РелизСтатусПримечание
dapper

released

2.1.19.dfsg1-0.1ubuntu2
devel

released

2.1.19.dfsg1-0.1ubuntu2
edgy

released

2.1.19.dfsg1-0.1ubuntu2
feisty

released

2.1.19.dfsg1-0.1ubuntu2
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

released

2.1.22.dfsg1-12
edgy

DNE

feisty

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

2.1.19-2
devel

DNE

edgy

released

2.1.19-2
feisty

released

2.1.19-2
upstream

needs-triage

Показывать по

Ссылки на источники

EPSS

Процентиль: 19%
0.0006
Низкий

7.2 High

CVSS2

Связанные уязвимости

redhat
больше 20 лет назад

The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASL_PATH to point to malicious programs.

nvd
больше 20 лет назад

The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASL_PATH to point to malicious programs.

debian
больше 20 лет назад

The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and ea ...

github
около 3 лет назад

The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASL_PATH to point to malicious programs.

fstec
больше 20 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 19%
0.0006
Низкий

7.2 High

CVSS2

Уязвимость CVE-2004-0884