PT-2004-1007 · Cyrus · Cyrus-Sasl

Josh Bressers

·

Publicado

2004-10-21

·

Atualizado

2017-10-11

·

CVE-2004-0884

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cyrus-SASL versions 2.1.18 and earlier
Description The issue allows local users to execute arbitrary code by modifying the SASL PATH environment variable to point to malicious programs, potentially leading to disruption of confidentiality, integrity, and availability of protected information. This is due to the libsasl and libsasl2 libraries trusting the SASL PATH environment variable to find all available SASL plug-ins.
Recommendations For Cyrus-SASL versions 2.1.18 and earlier, consider restricting access to the SASL PATH environment variable to prevent modification by local users until a patch is available. As a temporary workaround, avoid using the SASL PATH variable in sensitive operations. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-01744
CVE-2004-0884
DSA-563-3
DSA-568-1
RHSA-2004:546

Produtos afetados

Cyrus-Sasl