PT-2004-1007 · Cyrus · Cyrus-Sasl
Josh Bressers
·
Published
2004-10-21
·
Updated
2017-10-11
·
CVE-2004-0884
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cyrus-SASL versions 2.1.18 and earlier
Description
The issue allows local users to execute arbitrary code by modifying the
SASL PATH environment variable to point to malicious programs, potentially leading to disruption of confidentiality, integrity, and availability of protected information. This is due to the libsasl and libsasl2 libraries trusting the SASL PATH environment variable to find all available SASL plug-ins.Recommendations
For Cyrus-SASL versions 2.1.18 and earlier, consider restricting access to the
SASL PATH environment variable to prevent modification by local users until a patch is available. As a temporary workaround, avoid using the SASL PATH variable in sensitive operations.
At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cyrus-Sasl