Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Slackware 12.2: 2009-134-01 Critical: Buffer Overflow in Cyrus-SASL

slackware
Calendar Grey May 15, 2009
Dist Slackware Esm H88
The latest Cyrus-SASL patch for Slackware addresses a severe memory corruption vulnerability that poses risks of system instability.
New cyrus-sasl packages are available for Slackware 10.2, 11.0, 12.0, 12.1, 12.2, and -current to fix a security issue

Summary

Here are the details from the Slackware 12.2 ChangeLog: patches/packages/cyrus-sasl-2.1.23-i486-1_slack12.2.tgz: Upgraded to cyrus-sasl-2.1.23. This fixes a buffer overflow in the sasl_encode64() function that could lead to crashes or the execution of arbitrary code. For more information, see: https://www.cve.org/CVERecord?id=CVE-2009-0688 (* Security fix *)

Where Find New Packages

HINT: Getting slow download speeds from ftp.slackware.com? Give slackware.osuosl.org a try. This is another primary FTP site for Slackware that can be considerably faster than downloading directly from ftp.slackware.com.
Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating additional FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 10.2: ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/cyrus-sasl-2.1.23-i486-1_slack10.2.tgz
Updated package for Slackware 11.0: ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/cyrus-sasl-2.1.23-i486-1_slack11.0.tgz
Updated package for Slackware 12.0: ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/cyrus-sasl-2.1.23-i486-1_slack12.0.tgz
Updated package for Slackware 12.1: ftp://ftp.slackware.com/pub/slackware/slackware-...

Read the Full Advisory

MD5 Signatures

Slackware 10.2 package: e7715adc9687421e11ef18bc98a06d9b cyrus-sasl-2.1.23-i486-1_slack10.2.tgz
Slackware 11.0 package: 9f283935b166b44fa321d89594c828bd cyrus-sasl-2.1.23-i486-1_slack11.0.tgz
Slackware 12.0 package: 03d5b6ea37db7e6c9a69eb2d70f45368 cyrus-sasl-2.1.23-i486-1_slack12.0.tgz
Slackware 12.1 package: e472a88dee87be4f0f8a0cdb26b71f19 cyrus-sasl-2.1.23-i486-1_slack12.1.tgz
Slackware 12.2 package: 76ba85de3bde65d3d48cd6643b9a63b8 cyrus-sasl-2.1.23-i486-1_slack12.2.tgz
Slackware -current package: 089ed7728db2130f30bcf7504f961d00 cyrus-sasl-2.1.23-i486-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg cyrus-sasl-2.1.23-i486-1_slack12.2.tgz Then, restart any network services (such as sendmail) that use the SASL libraries.

Related News

Your message here