CRITICAL
security flaw
Published Dec 11, 2002
9.8
CRITICALCVSS 3.1
EPSS 7.08%
Description
Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.
Affected products
No data.
Configuration 1
- ≤ 2.1.9
Configuration 2
OR
- < 10.3.8
- < 10.3.8
No data.
Red Hat Linux 8.0
n/a
Fixed · RHSA-2002:283
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Linux 8.0 | n/a | Fixed | RHSA-2002:283 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (18)
- http://archives.neohapsis.com/archives/linux/suse/2002-q4/1275.html vendor-advisoryx_refsource_SUSEBroken Link
- http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000557 vendor-advisoryx_refsource_CONECTIVABroken Link
- http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html vendor-advisoryx_refsource_APPLEMailing List
- http://marc.info/?l=bugtraq&m=103946297703402&w=2 mailing-listx_refsource_BUGTRAQMailing ListPatch
- http://www.debian.org/security/2002/dsa-215 vendor-advisoryx_refsource_DEBIANBroken Link
- http://www.redhat.com/support/errata/RHSA-2002-283.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.securityfocus.com/advisories/4826 vendor-advisoryx_refsource_GENTOOBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/6347 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/6348 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/6349 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2002-1347 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1616880 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2002-1331 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10810 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10811 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10812 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2002-1347
- https://www.cve.org/CVERecord?id=CVE-2002-1347
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 11, 2002
Updated Aug 8, 2024
Reserved Dec 10, 2002
Link CVE-2002-1347
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2002-1331 Assigner mitre
Published Dec 11, 2002
Updated Aug 8, 2024
Exploited since n/a
Link EUVD-2002-1331