Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2002-1347

Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.1
EPSS Ranking 92.6%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
References
Products affected by CVE-2002-1347


Contact Us

Shodan ® - All rights reserved