Lucene search

K
osvGoogleOSV:USN-5301-2
HistoryFeb 22, 2022 - 9:37 p.m.

cyrus-sasl2 vulnerability

2022-02-2221:37:43
Google
osv.dev
4

9.1 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.2%

USN-5301-1 fixed a vulnerability in Cyrus. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.

Original advisory details:

It was discovered that the Cyrus SASL SQL plugin incorrectly handled SQL
input. A remote attacker could use this issue to execute arbitrary SQL
commands.