The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASL_PATH to point to malicious programs.
Software | From | Fixed in |
---|---|---|
conectiva / linux | 10.0 | 10.0.x |
conectiva / linux | 9.0 | 9.0.x |
cyrus / sasl | 1.5.24 | 1.5.24.x |
cyrus / sasl | 1.5.27 | 1.5.27.x |
cyrus / sasl | 1.5.28 | 1.5.28.x |
cyrus / sasl | 2.1.10 | 2.1.10.x |
cyrus / sasl | 2.1.11 | 2.1.11.x |
cyrus / sasl | 2.1.12 | 2.1.12.x |
cyrus / sasl | 2.1.13 | 2.1.13.x |
cyrus / sasl | 2.1.14 | 2.1.14.x |
cyrus / sasl | 2.1.15 | 2.1.15.x |
cyrus / sasl | 2.1.16 | 2.1.16.x |
cyrus / sasl | 2.1.17 | 2.1.17.x |
cyrus / sasl | 2.1.18 | 2.1.18.x |
cyrus / sasl | 2.1.18_r1 | 2.1.18_r1.x |
cyrus / sasl | 2.1.9 | 2.1.9.x |