Cyrus SASL Library CVE-2013-4122 NULL Pointer Dereference Denial of Service Vulnerability
BID:61164
Info
Cyrus SASL Library CVE-2013-4122 NULL Pointer Dereference Denial of Service Vulnerability
| Bugtraq ID: | 61164 |
| Class: | Design Error |
| CVE: |
CVE-2013-4122 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2013 12:00AM |
| Updated: | Nov 03 2015 07:51PM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
Cyrus SASL Library CVE-2013-4122 NULL Pointer Dereference Denial of Service Vulnerability
Cyrus SASL Library is prone to a denial-of-service vulnerability.
Successfully exploiting this issue will allow an attacker to crash the affected application, denying service to legitimate users.
Cyrus SASL Library 2.1.26 is vulnerable; other versions may also be affected.
Cyrus SASL Library is prone to a denial-of-service vulnerability.
Successfully exploiting this issue will allow an attacker to crash the affected application, denying service to legitimate users.
Cyrus SASL Library 2.1.26 is vulnerable; other versions may also be affected.
Exploit / POC
Cyrus SASL Library CVE-2013-4122 NULL Pointer Dereference Denial of Service Vulnerability
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
Solution / Fix
Cyrus SASL Library CVE-2013-4122 NULL Pointer Dereference Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cyrus SASL Library CVE-2013-4122 NULL Pointer Dereference Denial of Service Vulnerability
References:
References:
- CVE request: Cyrus-sasl NULL ptr. dereference (oss-security)
- Cyrus SASL Library Homepage (Carnegie Mellon University)
- SOL14901: SASL vulnerability CVE-2013-4122 (f5)