Search CVE reports
1 – 8 of 8 results
CVE-2022-24407
High priorityIn Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
1 affected package
cyrus-sasl2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cyrus-sasl2 | — | Fixed | Fixed | Fixed | Fixed |
CVE-2020-8032
Low priorityA Insecure Temporary File vulnerability in the packaging of cyrus-sasl of openSUSE Factory allows local attackers to escalate to root. This issue affects: openSUSE Factory cyrus-sasl version 2.1.27-4.2 and prior versions.
1 affected package
cyrus-sasl2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cyrus-sasl2 | — | Not affected | Not affected | Not affected | Not affected |
CVE-2019-19906
Medium prioritySome fixes available 4 of 5
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error...
1 affected package
cyrus-sasl2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cyrus-sasl2 | — | — | — | Fixed | Fixed |
CVE-2013-4122
Medium priorityCyrus SASL 2.1.23, 2.1.26, and earlier does not properly handle when a NULL value is returned upon an error by the crypt function as implemented in glibc 2.17 and later, which allows remote attackers to cause a denial of service...
1 affected package
cyrus-sasl2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cyrus-sasl2 | — | — | — | — | — |
CVE-2009-0688
Medium priorityMultiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via strings that are used as input to the sasl_encode64...
1 affected package
cyrus-sasl2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cyrus-sasl2 | — | — | — | — | — |
CVE-2006-1721
Unknown prioritydigestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via...
2 affected packages
cyrus-sasl2, cyrus-sasl2-heimdal
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cyrus-sasl2 | — | — | — | — | — |
cyrus-sasl2-heimdal | — | — | — | — | — |
CVE-2004-0884
Unknown priorityThe (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the...
3 affected packages
cyrus-sasl2, cyrus-sasl2-heimdal, cyrus-sasl2-mit
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cyrus-sasl2 | — | — | — | — | — |
cyrus-sasl2-heimdal | — | — | — | — | — |
cyrus-sasl2-mit | — | — | — | — | — |
CVE-2005-0373
Unknown priorityBuffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary code.
1 affected package
cyrus-sasl2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cyrus-sasl2 | — | — | — | — | — |