9.8
CVSSv3

CVE-2002-1347

Published: 18/12/2002 Updated: 02/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple buffer overflows in Cyrus SASL library 2.1.9 and previous versions allow remote malicious users to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.

Vulnerable Product Search on Vulmon Subscribe to Product

cyrusimap cyrus sasl

apple mac os x server

apple mac os x