ALT-PU-2015-1824-1
Package cyrus-sasl2 updated to version 2.1.24-alt7.cvs.20090508.M70C.2 for branch c7 in task 150648.
Closed vulnerabilities
Published: 2013-09-01
BDU:2015-09740
Уязвимость операционной системы Gentoo Linux, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации
Severity: MEDIUM (4.3)
References:
Published: 2013-10-27
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2013-4122
Cyrus SASL 2.1.23, 2.1.26, and earlier does not properly handle when a NULL value is returned upon an error by the crypt function as implemented in glibc 2.17 and later, which allows remote attackers to cause a denial of service (thread crash and consumption) via (1) an invalid salt or, when FIPS-140 is enabled, a (2) DES or (3) MD5 encrypted password, which triggers a NULL pointer dereference.
Severity: MEDIUM (4.3)
References:
- http://git.cyrusimap.org/cyrus-sasl/commit/?id=dedad73e5e7a75d01a5f3d5a6702ab8ccd2ff40d
- http://git.cyrusimap.org/cyrus-sasl/commit/?id=dedad73e5e7a75d01a5f3d5a6702ab8ccd2ff40d
- GLSA-201309-01
- GLSA-201309-01
- DSA-3368
- DSA-3368
- [oss-security] 20130712 CVE request: Cyrus-sasl NULL ptr. dereference
- [oss-security] 20130712 CVE request: Cyrus-sasl NULL ptr. dereference
- [oss-security] 20130712 Re: CVE request: Cyrus-sasl NULL ptr. dereference
- [oss-security] 20130712 Re: CVE request: Cyrus-sasl NULL ptr. dereference
- [oss-security] 20130713 Re: CVE request: Cyrus-sasl NULL ptr. dereference
- [oss-security] 20130713 Re: CVE request: Cyrus-sasl NULL ptr. dereference
- [oss-security] 20130715 Re: CVE request: Cyrus-sasl NULL ptr. dereference
- [oss-security] 20130715 Re: CVE request: Cyrus-sasl NULL ptr. dereference
- USN-2755-1
- USN-2755-1
- https://www.linuxquestions.org/questions/slackware-14/%5Bslackware-current%5D-glibc-2-17-shadow-and-other-penumbrae-4175461061/
- https://www.linuxquestions.org/questions/slackware-14/%5Bslackware-current%5D-glibc-2-17-shadow-and-other-penumbrae-4175461061/