Lucene search

K
redhatRedHatRHSA-2007:0878
HistorySep 04, 2007 - 12:00 a.m.

(RHSA-2007:0878) Moderate: cyrus-sasl security update

2007-09-0400:00:00
access.redhat.com
15

0.073 Low

EPSS

Percentile

94.1%

The cyrus-sasl package contains the Cyrus implementation of SASL.
SASL is the Simple Authentication and Security Layer, a method for
adding authentication support to connection-based protocols.

A bug was found in cyrus-sasl’s DIGEST-MD5 authentication mechanism. As
part of the DIGEST-MD5 authentication exchange, the client is expected to
send a specific set of information to the server. If one of these items
(the “realm”) was not sent or was malformed, it was possible for a remote
unauthenticated attacker to cause a denial of service (segmentation fault)
on the server. (CVE-2006-1721)

Users of cyrus-sasl should upgrade to these updated packages, which contain a
backported patch to correct this issue.