PT-2002-2764 · Cyrus · Cyrus-Sasl

Publicado

2002-12-31

·

Atualizado

2008-09-05

·

CVE-2002-2043

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cyrus SASL versions 1.5.24 through 1.5.27
Description The issue allows remote attackers to execute arbitrary SQL commands and log in as arbitrary POP mail users via the password, due to a SQL injection vulnerability in the LDAP and MySQL authentication patch.
Recommendations For Cyrus SASL versions 1.5.24 through 1.5.27, consider disabling the LDAP and MySQL authentication patch until a patch is available. Restrict access to the authentication module to minimize the risk of exploitation. Avoid using the password parameter in the affected authentication endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-2043

Produtos afetados

Cyrus-Sasl