The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASL_PATH to point to malicious programs.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Cyrussasl | — | Apply OS X security update 2005-003 | Dec 16, 2011 | Jan 27, 2005 |
| Debian | — | Upgrade cyrus-sasl2 | Jul 30, 2024 | Jan 27, 2005 |
| Freebsd | — | Upgrade cyrus-sasl | Dec 10, 2025 | Oct 8, 2004 |
| Gentoo Linux | — | Upgrade dev-libs/cyrus-sasl. | Oct 30, 2017 | Jan 27, 2005 |
| Suse | — | Upgrade cyrus-sasl-64bitUpgrade cyrus-sasl-devel-32bitUpgrade cyrus-sasl-develUpgrade cyrus-sasl-x86Upgrade cyrus-sasl-devel-64bitUpgrade cyrus-sasl-32bitUpgrade cyrus-sasl | Feb 17, 2015 | Jan 27, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub