CVE-2004-0884

The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASL_PATH to point to malicious programs.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cyrus:sasl:2.1.10:*:*:*:*:*:*:*
cpe:2.3:a:cyrus:sasl:2.1.11:*:*:*:*:*:*:*
cpe:2.3:a:cyrus:sasl:2.1.18:*:*:*:*:*:*:*
cpe:2.3:a:cyrus:sasl:2.1.18_r1:*:*:*:*:*:*:*
cpe:2.3:a:cyrus:sasl:2.1.9:*:*:*:*:*:*:*
cpe:2.3:a:cyrus:sasl:2.1.12:*:*:*:*:*:*:*
cpe:2.3:a:cyrus:sasl:2.1.13:*:*:*:*:*:*:*
cpe:2.3:o:conectiva:linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:conectiva:linux:9.0:*:*:*:*:*:*:*
cpe:2.3:a:cyrus:sasl:1.5.24:*:*:*:*:*:*:*
cpe:2.3:a:cyrus:sasl:2.1.14:*:*:*:*:*:*:*
cpe:2.3:a:cyrus:sasl:2.1.16:*:*:*:*:*:*:*
cpe:2.3:a:cyrus:sasl:1.5.27:*:*:*:*:*:*:*
cpe:2.3:a:cyrus:sasl:1.5.28:*:*:*:*:*:*:*
cpe:2.3:a:cyrus:sasl:2.1.17:*:*:*:*:*:*:*
cpe:2.3:a:cyrus:sasl:2.1.15:*:*:*:*:*:*:*

Information

Published : 2005-01-26 21:00

Updated : 2017-10-10 18:29


NVD link : CVE-2004-0884

Mitre link : CVE-2004-0884


JSON object : View

Advertisement

dedicated server usa

Products Affected

cyrus

  • sasl

conectiva

  • linux