Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora Core 2: 2004-331 Critical: cyrus-sasl Local Code Execution

fedora
Calendar Grey October 8, 2004
Dist Fedora Esm H88
Vital Ubuntu patch tackles security flaws that could enable local users to run unauthorized commands.
In situations where an untrusted local user can affect the environment of a privileged process, this behavior could be exploited to run arbitrary code with the privileges of a setu...

Summary

The cyrus-sasl package contains the Cyrus implementation of SASL.

SASL is the Simple Authentication and Security Layer, a method for

adding authentication support to connection-based protocols.

Update Information:

At application startup, libsasl and libsasl2 attempt to build a list of all SASL plug-ins which are available on the system. To do so, the libraries search for and attempt to load every shared library found within the plug-in directory. This location can be set with the SASL_PATH environment variable.

In situations where an untrusted local user can affect the environment of a privileged process, this behavior could be exploited to run arbitrary code with the privileges of a setuid or setgid application. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0884 to this issue.

Users of cyrus-sasl should upgrade to these updated packages, which contain backported patches and are not vulnerable to this issue.


* Thu Oct 07 2004 Nalin Dahyabhai <nalin@redhat.com> 2.1.18-2.2

- use notting's fix for incorrect patch for CAN-2004-0884 for 1.5.28

* Thu Oct 07 2004 Nalin Dahyabhai <nalin@redhat.com> 2.1.18-2.1

- don't trust the environme...

Read the Full Advisory

Change Log

References

Fedora Update Notification FEDORA-2004-331 2004-10-08
Product : Fedora Core 2 Name : cyrus-sasl Version : 2.1.18 Release : 2.2 Summary : The Cyrus SASL library. Description : The cyrus-sasl package contains the Cyrus implementation of SASL. SASL is the Simple Authentication and Security Layer, a method for adding authentication support to connection-based protocols.

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora Core 2
Name: cyrus-sasl
Version: 2.1.18
Release: 2.2
Summary: The Cyrus SASL library.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here