GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Fri Apr 21, 2006 6:26 am Post subject: [ GLSA 200604-09 ] Cyrus-SASL: DIGEST-MD5 Pre-Authentication |
|
|
Gentoo Linux Security Advisory
Title: Cyrus-SASL: DIGEST-MD5 Pre-Authentication Denial of Service (GLSA 200604-09)
Severity: normal
Exploitable: remote
Date: April 21, 2006
Bug(s): #129523
ID: 200604-09
Synopsis
Cyrus-SASL contains a vulnerability in the DIGEST-MD5 process that could lead to a Denial of Service.
Background
Cyrus-SASL is an implementation of the Simple Authentication and Security Layer.
Affected Packages
Package: dev-libs/cyrus-sasl
Vulnerable: < 2.1.21-r2
Unaffected: >= 2.1.21-r2
Architectures: All supported architectures
Description
Cyrus-SASL contains an unspecified vulnerability in the DIGEST-MD5 process that could lead to a Denial of Service.
Impact
An attacker could possibly exploit this vulnerability by sending specially crafted data stream to the Cyrus-SASL server, resulting in a Denial of Service even if the attacker is not able to authenticate.
Workaround
There is no known workaround at this time.
Resolution
All Cyrus-SASL users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=dev-libs/cyrus-sasl-2.1.21-r2" |
References
CVE-2006-1721
Last edited by GLSA on Sun May 07, 2006 5:01 pm; edited 1 time in total |
|