Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary code.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade cyrus-sasl2 | Jul 30, 2024 | Oct 7, 2004 |
| Gentoo Linux | — | Upgrade dev-libs/cyrus-sasl. | Oct 30, 2017 | Oct 7, 2004 |
| Suse | — | Upgrade cyrus-sasl-x86Upgrade cyrus-saslUpgrade cyrus-sasl-64bitUpgrade cyrus-sasl-32bit | Feb 17, 2015 | Oct 7, 2004 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub