CVE-2002-1347

Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.
References
Link Resource
http://archives.neohapsis.com/archives/linux/suse/2002-q4/1275.html Broken Link
http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000557 Broken Link
http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html Mailing List
http://marc.info/?l=bugtraq&m=103946297703402&w=2 Mailing List Patch
http://www.debian.org/security/2002/dsa-215 Broken Link
http://www.redhat.com/support/errata/RHSA-2002-283.html Broken Link
http://www.securityfocus.com/advisories/4826 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/6347 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/6348 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/6349 Broken Link Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/10810 Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/10811 Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/10812 Third Party Advisory VDB Entry
http://archives.neohapsis.com/archives/linux/suse/2002-q4/1275.html Broken Link
http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000557 Broken Link
http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html Mailing List
http://marc.info/?l=bugtraq&m=103946297703402&w=2 Mailing List Patch
http://www.debian.org/security/2002/dsa-215 Broken Link
http://www.redhat.com/support/errata/RHSA-2002-283.html Broken Link
http://www.securityfocus.com/advisories/4826 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/6347 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/6348 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/6349 Broken Link Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/10810 Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/10811 Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/10812 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:cyrusimap:cyrus_sasl:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:41

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/linux/suse/2002-q4/1275.html - Broken Link () http://archives.neohapsis.com/archives/linux/suse/2002-q4/1275.html - Broken Link
References () http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000557 - Broken Link () http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000557 - Broken Link
References () http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html - Mailing List () http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html - Mailing List
References () http://marc.info/?l=bugtraq&m=103946297703402&w=2 - Mailing List, Patch () http://marc.info/?l=bugtraq&m=103946297703402&w=2 - Mailing List, Patch
References () http://www.debian.org/security/2002/dsa-215 - Broken Link () http://www.debian.org/security/2002/dsa-215 - Broken Link
References () http://www.redhat.com/support/errata/RHSA-2002-283.html - Broken Link () http://www.redhat.com/support/errata/RHSA-2002-283.html - Broken Link
References () http://www.securityfocus.com/advisories/4826 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/advisories/4826 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/6347 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/6347 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/6348 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/6348 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/6349 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/6349 - Broken Link, Third Party Advisory, VDB Entry
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/10810 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/10810 - Third Party Advisory, VDB Entry
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/10811 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/10811 - Third Party Advisory, VDB Entry
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/10812 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/10812 - Third Party Advisory, VDB Entry

02 Feb 2024, 03:05

Type Values Removed Values Added
CVSS v2 : 7.5
v3 : unknown
v2 : 7.5
v3 : 9.8
CPE cpe:2.3:a:cyrus:sasl:*:*:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x_server:*:*:*:*:*:*:*:*
cpe:2.3:a:cyrusimap:cyrus_sasl:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
First Time Cyrusimap
Cyrusimap cyrus Sasl
Apple
Apple mac Os X
Apple mac Os X Server
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/10810 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/10810 - Third Party Advisory, VDB Entry
References (CONECTIVA) http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000557 - (CONECTIVA) http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000557 - Broken Link
References (BUGTRAQ) http://marc.info/?l=bugtraq&m=103946297703402&w=2 - (BUGTRAQ) http://marc.info/?l=bugtraq&m=103946297703402&w=2 - Mailing List, Patch
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/10811 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/10811 - Third Party Advisory, VDB Entry
References (REDHAT) http://www.redhat.com/support/errata/RHSA-2002-283.html - (REDHAT) http://www.redhat.com/support/errata/RHSA-2002-283.html - Broken Link
References (GENTOO) http://www.securityfocus.com/advisories/4826 - (GENTOO) http://www.securityfocus.com/advisories/4826 - Broken Link, Third Party Advisory, VDB Entry
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/10812 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/10812 - Third Party Advisory, VDB Entry
References (DEBIAN) http://www.debian.org/security/2002/dsa-215 - (DEBIAN) http://www.debian.org/security/2002/dsa-215 - Broken Link
References (SUSE) http://archives.neohapsis.com/archives/linux/suse/2002-q4/1275.html - (SUSE) http://archives.neohapsis.com/archives/linux/suse/2002-q4/1275.html - Broken Link
References (BID) http://www.securityfocus.com/bid/6348 - (BID) http://www.securityfocus.com/bid/6348 - Broken Link, Third Party Advisory, VDB Entry
References (BID) http://www.securityfocus.com/bid/6347 - (BID) http://www.securityfocus.com/bid/6347 - Broken Link, Third Party Advisory, VDB Entry
References (BID) http://www.securityfocus.com/bid/6349 - (BID) http://www.securityfocus.com/bid/6349 - Broken Link, Third Party Advisory, VDB Entry
References (APPLE) http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html - (APPLE) http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html - Mailing List
CWE NVD-CWE-Other CWE-131

Information

Published : 2002-12-18 05:00

Updated : 2024-11-20 23:41


NVD link : CVE-2002-1347

Mitre link : CVE-2002-1347

CVE.ORG link : CVE-2002-1347


JSON object : View

Products Affected

cyrusimap

  • cyrus_sasl

apple

  • mac_os_x
  • mac_os_x_server
CWE
CWE-131

Incorrect Calculation of Buffer Size