ALAS-2014-338 ---- cyrus-saslID: oval:org.secpod.oval:def:1600097 | Date: (C)2016-01-07 (M)2022-10-10 |
Class: PATCH | Family: unix |
Cyrus SASL 2.1.23, 2.1.26, and earlier does not properly handle when a NULL value is returned upon an error by the crypt function as implemented in glibc 2.17 and later, which allows remote attackers to cause a denial of service via an invalid salt or, when FIPS-140 is enabled, a DES or MD5 encrypted password, which triggers a NULL pointer dereference.
Platform: |
Amazon Linux AMI |