The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASL_PATH to point to malicious programs.
2005-01-27T05:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.2 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cyrus | sasl | 1.5.24 | Yes |
Application | cyrus | sasl | 1.5.27 | Yes |
Application | cyrus | sasl | 1.5.28 | Yes |
Application | cyrus | sasl | 2.1.9 | Yes |
Application | cyrus | sasl | 2.1.10 | Yes |
Application | cyrus | sasl | 2.1.11 | Yes |
Application | cyrus | sasl | 2.1.12 | Yes |
Application | cyrus | sasl | 2.1.13 | Yes |
Application | cyrus | sasl | 2.1.14 | Yes |
Application | cyrus | sasl | 2.1.15 | Yes |
Application | cyrus | sasl | 2.1.16 | Yes |
Application | cyrus | sasl | 2.1.17 | Yes |
Application | cyrus | sasl | 2.1.18 | Yes |
Application | cyrus | sasl | 2.1.18_r1 | Yes |
Operating System | conectiva | linux | 9.0 | Yes |
Operating System | conectiva | linux | 10.0 | Yes |