CVE-2002-1347
Summary
| CVE | CVE-2002-1347 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-12-18 05:00:00 UTC |
| Updated | 2024-02-02 03:05:00 UTC |
| Description | Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string. |
Risk And Classification
Problem Types: CWE-131
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Mac Os X | All | All | All | All |
| Operating System | Apple | Mac Os X Server | All | All | All | All |
| Application | Cyrus | Sasl | All | All | All | All |
| Application | Cyrusimap | Cyrus Sasl | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 'Cyrus SASL library buffer overflows' - MARC | BUGTRAQ | marc.info | |
| Cyrus SASL Library Logging Memory Corruption Vulnerability | BID | www.securityfocus.com | |
| Cyrus SASL Library Username Heap Corruption Vulnerability | BID | www.securityfocus.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Debian -- Security Information -- DSA-215-1 cyrus-imapd | DEBIAN | www.debian.org | |
| Neohapsis Archives - SuSE Security Discussion - [suse-security] SuSE Security Announcement: cyrus-imapd (SuSE-SA:2002:048) - From krahmer_at_suse.de | SUSE | archives.neohapsis.com | |
| 200212-10 | GENTOO | www.securityfocus.com | |
| APPLE-SA-2005-03-21 Security Update 2005-003 | APPLE | lists.apple.com | |
| redhat.com | Red Hat Support | REDHAT | www.redhat.com | |
| 000557 | CONECTIVA | distro.conectiva.com | |
| Cyrus SASL Library LDAP Heap Corruption Vulnerability | BID | www.securityfocus.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.