Cyrus SASL Library LDAP Heap Corruption Vulnerability
BID:6348
Info
Cyrus SASL Library LDAP Heap Corruption Vulnerability
| Bugtraq ID: | 6348 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-1347 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2002 12:00AM |
| Updated: | Jul 11 2009 07:16PM |
| Credit: | Discovery of this vulnerability is credited to Timo Sirainen <[email protected]>. |
| Vulnerable: |
Cyrus-Utils SASL 2.1.9 Apple Mac OS X Server 10.3.8 Apple Mac OS X Server 10.3.7 Apple Mac OS X Server 10.3.6 Apple Mac OS X Server 10.3.5 Apple Mac OS X Server 10.3.4 Apple Mac OS X Server 10.3.3 Apple Mac OS X Server 10.3.2 Apple Mac OS X Server 10.3.1 Apple Mac OS X Server 10.3 Apple Mac OS X Server 10.2.8 Apple Mac OS X Server 10.2.7 Apple Mac OS X Server 10.2.6 Apple Mac OS X Server 10.2.5 Apple Mac OS X Server 10.2.4 Apple Mac OS X Server 10.2.3 Apple Mac OS X Server 10.2.2 Apple Mac OS X Server 10.2.1 Apple Mac OS X Server 10.2 Apple Mac OS X Server 10.1.5 Apple Mac OS X Server 10.1.4 Apple Mac OS X Server 10.1.3 Apple Mac OS X Server 10.1.2 Apple Mac OS X Server 10.1.1 Apple Mac OS X Server 10.1 Apple Mac OS X Server 10.0 Apple Mac OS X 10.3.8 Apple Mac OS X 10.3.7 Apple Mac OS X 10.3.6 Apple Mac OS X 10.3.5 Apple Mac OS X 10.3.4 Apple Mac OS X 10.3.3 Apple Mac OS X 10.3.2 Apple Mac OS X 10.3.1 Apple Mac OS X 10.3 Apple Mac OS X 10.2.8 Apple Mac OS X 10.2.7 Apple Mac OS X 10.2.6 Apple Mac OS X 10.2.5 Apple Mac OS X 10.2.4 Apple Mac OS X 10.2.3 Apple Mac OS X 10.2.2 Apple Mac OS X 10.2.1 Apple Mac OS X 10.2 Apple Mac OS X 10.1.5 Apple Mac OS X 10.1.4 Apple Mac OS X 10.1.3 Apple Mac OS X 10.1.2 Apple Mac OS X 10.1.1 Apple Mac OS X 10.1 Apple Mac OS X 10.1 Apple Mac OS X 10.0.4 Apple Mac OS X 10.0.3 Apple Mac OS X 10.0.2 Apple Mac OS X 10.0.1 Apple Mac OS X 10.0 3 Apple Mac OS X 10.0 |
| Not Vulnerable: |
Cyrus-Utils SASL 2.1.10 Cyrus-Utils SASL 1.5.28 |
Discussion
Cyrus SASL Library LDAP Heap Corruption Vulnerability
A heap corruption vulnerability has been discovered in Cyrus SASL library. It has been discovered that SASL fails to allocate sufficient memory when it is required to escape characters. This may allow an attacker to overwrite sensitive heap memory. By overwriting malloc headers it may be possible for an attacker to cause an arbitrary location in memory to be overwritten with a malicious value.
Successful exploitation of this issue may allow an attacker to execute arbitrary code with the privileges of the vulnerable application.
It should be noted that although this vulnerability was discovered in Cyrus, it may also affect other programs that utilize the SASL library.
A heap corruption vulnerability has been discovered in Cyrus SASL library. It has been discovered that SASL fails to allocate sufficient memory when it is required to escape characters. This may allow an attacker to overwrite sensitive heap memory. By overwriting malloc headers it may be possible for an attacker to cause an arbitrary location in memory to be overwritten with a malicious value.
Successful exploitation of this issue may allow an attacker to execute arbitrary code with the privileges of the vulnerable application.
It should be noted that although this vulnerability was discovered in Cyrus, it may also affect other programs that utilize the SASL library.
Exploit / POC
Cyrus SASL Library LDAP Heap Corruption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Cyrus SASL Library LDAP Heap Corruption Vulnerability
Solution:
It is recommended that all Gentoo Linux users who are running
dev-libs/cyrus-sasl-2.1.9 update their systems as follows:
emerge rsync
emerge cyrus-sasl
emerge clean
This issue has been fixed in version 2.1.10. Users are advised to upgrade as soon as possible.
Apple has released advisory (Security Update 2005-003) to address various issues. Please see the referenced advisory for more information. Updates for Mac OS X v10.3.8 and Mac OS X Server v10.3.8 are available.
Apple Mac OS X 10.3.8
Apple Mac OS X Server 10.3.8
Cyrus-Utils SASL 2.1.9
Solution:
It is recommended that all Gentoo Linux users who are running
dev-libs/cyrus-sasl-2.1.9 update their systems as follows:
emerge rsync
emerge cyrus-sasl
emerge clean
This issue has been fixed in version 2.1.10. Users are advised to upgrade as soon as possible.
Apple has released advisory (Security Update 2005-003) to address various issues. Please see the referenced advisory for more information. Updates for Mac OS X v10.3.8 and Mac OS X Server v10.3.8 are available.
Apple Mac OS X 10.3.8
-
Apple SecUpd2005-003Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=05529&plat form=osx&method=sa/SecUpd2005-003Pan.dmg
Apple Mac OS X Server 10.3.8
-
Apple SecUpdSrvr2005-003Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=05530&plat form=osx&method=sa/SecUpdSrvr2005-003Pan.dmg
Cyrus-Utils SASL 2.1.9
-
Cyrus SASL 2.1.10
ftp://ftp.andrew.cmu.edu/pub/cyrus-mail/cyrus-sasl-2.1.10.tar.gz -
RedHat cyrus-sasl-2.1.10-1.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/cyrus-sasl-2.1.10-1.i386.rpm -
RedHat cyrus-sasl-devel-2.1.10-1.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/cyrus-sasl-devel-2.1.10-1.i386 .rpm -
RedHat cyrus-sasl-gssapi-2.1.10-1.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/cyrus-sasl-gssapi-2.1.10-1.i38 6.rpm -
RedHat cyrus-sasl-md5-2.1.10-1.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/cyrus-sasl-md5-2.1.10-1.i386.r pm -
RedHat cyrus-sasl-plain-2.1.10-1.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/cyrus-sasl-plain-2.1.10-1.i386 .rpm
References
Cyrus SASL Library LDAP Heap Corruption Vulnerability
References:
References:
- About Security Update 2005-003 (Apple)
- Cyrus SASL library buffer overflows (Timo Sirainen
)