Vulnerabilities > CVE-2001-0869

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
caldera
redhat
suse
nessus

Summary

Format string vulnerability in the default logging callback function _sasl_syslog in common.c in Cyrus SASL library (cyrus-sasl) may allow remote attackers to execute arbitrary commands.

Nessus

NASL familyMandriva Local Security Checks
NASL idMANDRAKE_MDKSA-2002-018.NASL
descriptionKari Hurtta discovered that a format bug exists in the Cyrus SASL library, which is used to provide an authentication API for mail clients and servers, as well as other services such as LDAP. The format bug was found in one of the logging functions which could be used by an attacker to obtain access to a machine or to possibly acquire elevated privileges. Thanks to the SuSE security team for providing the fix.
last seen2020-06-01
modified2020-06-02
plugin id13926
published2004-07-31
reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/13926
titleMandrake Linux Security Advisory : cyrus-sasl (MDKSA-2002:018)

Redhat

advisories
  • rhsa
    idRHSA-2001:150
  • rhsa
    idRHSA-2001:151