CVE-2002-1347

Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.
References
Link Resource
http://archives.neohapsis.com/archives/linux/suse/2002-q4/1275.html Broken Link
http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000557 Broken Link
http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html Mailing List
http://marc.info/?l=bugtraq&m=103946297703402&w=2 Mailing List Patch
http://www.debian.org/security/2002/dsa-215 Broken Link
http://www.redhat.com/support/errata/RHSA-2002-283.html Broken Link
http://www.securityfocus.com/advisories/4826 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/6347 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/6348 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/6349 Broken Link Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/10810 Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/10811 Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/10812 Third Party Advisory VDB Entry
http://archives.neohapsis.com/archives/linux/suse/2002-q4/1275.html Broken Link
http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000557 Broken Link
http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html Mailing List
http://marc.info/?l=bugtraq&m=103946297703402&w=2 Mailing List Patch
http://www.debian.org/security/2002/dsa-215 Broken Link
http://www.redhat.com/support/errata/RHSA-2002-283.html Broken Link
http://www.securityfocus.com/advisories/4826 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/6347 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/6348 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/6349 Broken Link Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/10810 Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/10811 Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/10812 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:cyrusimap:cyrus_sasl:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2002-12-18 05:00

Updated : 2025-04-03 01:03


NVD link : CVE-2002-1347

Mitre link : CVE-2002-1347

CVE.ORG link : CVE-2002-1347


JSON object : View

Products Affected

apple

  • mac_os_x
  • mac_os_x_server

cyrusimap

  • cyrus_sasl
CWE
CWE-131

Incorrect Calculation of Buffer Size