Download
| Alert*
oval:org.secpod.oval:def:602239
It was discovered that cyrus-sasl2, a library implementing the Simple Authentication and Security Layer, does not properly handle certain invalid password salts. A remote attacker can take advantage of this flaw to cause a denial of service. oval:org.secpod.oval:def:1600097 Cyrus SASL 2.1.23, 2.1.26, and earlier does not properly handle when a NULL value is returned upon an error by the crypt function as implemented in glibc 2.17 and later, which allows remote attackers to cause a denial of service via an invalid salt or, when FIPS-140 is enabled, a DES or MD5 encr ... oval:org.secpod.oval:def:702773 cyrus-sasl2: Cyrus Simple Authentication and Security Layer Cyrus SASL could be made to crash if it processed specially crafted input. oval:org.secpod.oval:def:701447 cyrus-sasl2: Cyrus Simple Authentication and Security Layer Cyrus SASL could be made to crash if it processed specially crafted input. |