    Debian: cyrus-sasl arbitrary code execution fix

    Date 14 Oct 2004
    Posted By LinuxSecurity Advisories
    This advisory is an addition to DSA 563-1 and 563-2 which weren't ableto supersede the library on sparc and arm due to a different versionnumber for them in the stable archive.
    Debian Security Advisory DSA 563-3                     This email address is being protected from spambots. You need JavaScript enabled to view it.                             Martin Schulze
    October 14th, 2004             
    Package        : cyrus-sasl
    Vulnerability  : unsanitised input
    Problem-Type   : local
    Debian-specific: no
    CVE ID         : CAN-2004-0884
    Debian Bug     : 275498
    This advisory is an addition to DSA 563-1 and 563-2 which weren't able
    to supersede the library on sparc and arm due to a different version
    number for them in the stable archive.  Other architectures were
    updated properly.  Another problem was reported in connection with
    sendmail, though, which should be fixed with this update as well.
    For the stable distribution (woody) this problem has been fixed in
    version 1.5.27-3.1woody5.
    For reference the advisory text follows:
      A vulnerability has been discovered in the Cyrus implementation of
      the SASL library, the Simple Authentication and Security Layer, a
      method for adding authentication support to connection-based
      protocols.  The library honors the environment variable SASL_PATH
      blindly, which allows a local user to link against a malicious
      library to run arbitrary code with the privileges of a setuid or
      setgid application.
      For the unstable distribution (sid) this problem has been fixed in
      version 1.5.28-6.2 of cyrus-sasl and in version 2.1.19-1.3 of
    We recommend that you upgrade your libsasl packages.
    Upgrade Instructions
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    Debian GNU/Linux 3.0 alias woody
      Source archives:
      These files will probably be moved into the stable distribution on
      its next update.
    For apt-get: deb stable/updates main
    For dpkg-ftp: dists/stable/updates/main
    Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it.
    Package info: `apt-cache show ' and


