Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2004-0884
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-0884

Description:
The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASL_PATH to point to malicious programs.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/17643

TRUSTIX
  http://www.trustix.net/errata/2004/0053/

REDHAT
  http://rhn.redhat.com/errata/RHSA-2004-546.html

MANDRAKE
  http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:106

GENTOO
  http://www.gentoo.org/security/en/glsa/glsa-200410-05.xml

FEDORA

DEBIAN
  http://www.debian.org/security/2004/dsa-568
  http://www.debian.org/security/2004/dsa-563

CONFIRM
  http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=134657

CIAC
  http://www.ciac.org/ciac/bulletins/p-003.shtml

BUGTRAQ
  http://marc.theaimsgroup.com/?l=bugtraq&m=110693126007214&w=2

BID
  11347

APPLE
  http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html


Return to the previous page.