CVE-2002-1347

Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.
References
Link Resource
http://archives.neohapsis.com/archives/linux/suse/2002-q4/1275.html Broken Link
http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000557 Broken Link
http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html Mailing List
http://marc.info/?l=bugtraq&m=103946297703402&w=2 Mailing List Patch
http://www.debian.org/security/2002/dsa-215 Broken Link
http://www.redhat.com/support/errata/RHSA-2002-283.html Broken Link
http://www.securityfocus.com/advisories/4826 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/6347 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/6348 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/6349 Broken Link Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/10810 Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/10811 Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/10812 Third Party Advisory VDB Entry
http://archives.neohapsis.com/archives/linux/suse/2002-q4/1275.html Broken Link
http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000557 Broken Link
http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html Mailing List
http://marc.info/?l=bugtraq&m=103946297703402&w=2 Mailing List Patch
http://www.debian.org/security/2002/dsa-215 Broken Link
http://www.redhat.com/support/errata/RHSA-2002-283.html Broken Link
http://www.securityfocus.com/advisories/4826 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/6347 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/6348 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/6349 Broken Link Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/10810 Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/10811 Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/10812 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:cyrusimap:cyrus_sasl:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:41

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/linux/suse/2002-q4/1275.html - Broken Link () http://archives.neohapsis.com/archives/linux/suse/2002-q4/1275.html - Broken Link
References () http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000557 - Broken Link () http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000557 - Broken Link
References () http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html - Mailing List () http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html - Mailing List
References () http://marc.info/?l=bugtraq&m=103946297703402&w=2 - Mailing List, Patch () http://marc.info/?l=bugtraq&m=103946297703402&w=2 - Mailing List, Patch
References () http://www.debian.org/security/2002/dsa-215 - Broken Link () http://www.debian.org/security/2002/dsa-215 - Broken Link
References () http://www.redhat.com/support/errata/RHSA-2002-283.html - Broken Link () http://www.redhat.com/support/errata/RHSA-2002-283.html - Broken Link
References () http://www.securityfocus.com/advisories/4826 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/advisories/4826 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/6347 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/6347 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/6348 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/6348 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/6349 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/6349 - Broken Link, Third Party Advisory, VDB Entry
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/10810 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/10810 - Third Party Advisory, VDB Entry
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/10811 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/10811 - Third Party Advisory, VDB Entry
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/10812 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/10812 - Third Party Advisory, VDB Entry

02 Feb 2024, 03:05

Type Values Removed Values Added
First Time Cyrusimap
Apple
Cyrusimap cyrus Sasl
Apple mac Os X
Apple mac Os X Server
CPE cpe:2.3:a:cyrus:sasl:*:*:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x_server:*:*:*:*:*:*:*:*
cpe:2.3:a:cyrusimap:cyrus_sasl:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
CWE NVD-CWE-Other CWE-131
CVSS v2 : 7.5
v3 : unknown
v2 : 7.5
v3 : 9.8
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/10812 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/10812 - Third Party Advisory, VDB Entry
References (DEBIAN) http://www.debian.org/security/2002/dsa-215 - (DEBIAN) http://www.debian.org/security/2002/dsa-215 - Broken Link
References (BUGTRAQ) http://marc.info/?l=bugtraq&m=103946297703402&w=2 - (BUGTRAQ) http://marc.info/?l=bugtraq&m=103946297703402&w=2 - Mailing List, Patch
References (CONECTIVA) http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000557 - (CONECTIVA) http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000557 - Broken Link
References (SUSE) http://archives.neohapsis.com/archives/linux/suse/2002-q4/1275.html - (SUSE) http://archives.neohapsis.com/archives/linux/suse/2002-q4/1275.html - Broken Link
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/10811 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/10811 - Third Party Advisory, VDB Entry
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/10810 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/10810 - Third Party Advisory, VDB Entry
References (BID) http://www.securityfocus.com/bid/6347 - (BID) http://www.securityfocus.com/bid/6347 - Broken Link, Third Party Advisory, VDB Entry
References (BID) http://www.securityfocus.com/bid/6349 - (BID) http://www.securityfocus.com/bid/6349 - Broken Link, Third Party Advisory, VDB Entry
References (BID) http://www.securityfocus.com/bid/6348 - (BID) http://www.securityfocus.com/bid/6348 - Broken Link, Third Party Advisory, VDB Entry
References (REDHAT) http://www.redhat.com/support/errata/RHSA-2002-283.html - (REDHAT) http://www.redhat.com/support/errata/RHSA-2002-283.html - Broken Link
References (GENTOO) http://www.securityfocus.com/advisories/4826 - (GENTOO) http://www.securityfocus.com/advisories/4826 - Broken Link, Third Party Advisory, VDB Entry
References (APPLE) http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html - (APPLE) http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html - Mailing List

Information

Published : 2002-12-18 05:00

Updated : 2025-04-03 01:03


NVD link : CVE-2002-1347

Mitre link : CVE-2002-1347

CVE.ORG link : CVE-2002-1347


JSON object : View

Products Affected

apple

  • mac_os_x
  • mac_os_x_server

cyrusimap

  • cyrus_sasl
CWE
CWE-131

Incorrect Calculation of Buffer Size