Gentoo Archives: gentoo-announce

From: Kurt Lieber <klieber@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200410-05 ] Cyrus-SASL: Buffer overflow and SASL_PATH vulnerabilities
Date: Thu, 07 Oct 2004 14:05:35
Message-Id: 20041007140350.GQ26288@mail.lieber.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200410-05
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: Cyrus-SASL: Buffer overflow and SASL_PATH vulnerabilities
9 Date: October 07, 2004
10 Bugs: #56016
11 ID: 200410-05
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Cyrus-SASL contains two vulnerabilities that might allow an attacker to
19 completely compromise the vulnerable system.
20
21 Background
22 ==========
23
24 Cyrus-SASL is an implementation of the Simple Authentication and
25 Security Layer.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 dev-libs/cyrus-sasl <= 2.1.18-r1 >= 2.1.18-r2
34
35 Description
36 ===========
37
38 Cyrus-SASL contains a remote buffer overflow in the digestmda5.c file.
39 Additionally, under certain conditions it is possible for a local user
40 to exploit a vulnerability in the way the SASL_PATH environment
41 variable is honored (CAN-2004-0884).
42
43 Impact
44 ======
45
46 An attacker might be able to execute arbitrary code with the Effective
47 ID of the application calling the Cyrus-SASL libraries.
48
49 Workaround
50 ==========
51
52 There is no known workaround at this time.
53
54 Resolution
55 ==========
56
57 All Cyrus-SASL users should upgrade to the latest stable version:
58
59 # emerge sync
60
61 # emerge -pv ">=dev-libs/cyrus-sasl-2.1.18-r2"
62 # emerge ">=dev-libs/cyrus-sasl-2.1.18-r2"
63
64 References
65 ==========
66
67 [ 1 ] CAN-2004-0884
68 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0884
69
70 Availability
71 ============
72
73 This GLSA and any updates to it are available for viewing at
74 the Gentoo Security Website:
75
76 http://security.gentoo.org/glsa/glsa-200410-05.xml
77
78 Concerns?
79 =========
80
81 Security is a primary focus of Gentoo Linux and ensuring the
82 confidentiality and security of our users machines is of utmost
83 importance to us. Any security concerns should be addressed to
84 security@g.o or alternatively, you may file a bug at
85 http://bugs.gentoo.org.
86
87 License
88 =======
89
90 Copyright 2004 Gentoo Foundation, Inc; referenced text
91 belongs to its owner(s).
92
93 The contents of this document are licensed under the
94 Creative Commons - Attribution / Share Alike license.
95
96 http://creativecommons.org/licenses/by-sa/1.0