Lucene search

K
freebsdFreeBSD14AB174C-40EF-11DE-9FD5-001BD3385381
HistoryApr 08, 2009 - 12:00 a.m.

cyrus-sasl -- buffer overflow vulnerability

2009-04-0800:00:00
vuxml.freebsd.org
16

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.407

Percentile

97.3%

US-CERT reports:

The sasl_encode64() function converts a string into
base64. The Cyrus SASL library contains buffer overflows
that occur because of unsafe use of the sasl_encode64()
function.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchcyrus-sasl< 2.1.23UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.407

Percentile

97.3%