Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2004-0884

The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASL_PATH to point to malicious programs.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 19.0%
CVSS Severity
CVSS v2 Score 7.2
References
Products affected by CVE-2004-0884
  • Cyrus » Sasl » Version: 1.5.24
    cpe:2.3:a:cyrus:sasl:1.5.24
  • Cyrus » Sasl » Version: 1.5.27
    cpe:2.3:a:cyrus:sasl:1.5.27
  • Cyrus » Sasl » Version: 1.5.28
    cpe:2.3:a:cyrus:sasl:1.5.28
  • Cyrus » Sasl » Version: 2.1.10
    cpe:2.3:a:cyrus:sasl:2.1.10
  • Cyrus » Sasl » Version: 2.1.11
    cpe:2.3:a:cyrus:sasl:2.1.11
  • Cyrus » Sasl » Version: 2.1.12
    cpe:2.3:a:cyrus:sasl:2.1.12
  • Cyrus » Sasl » Version: 2.1.13
    cpe:2.3:a:cyrus:sasl:2.1.13
  • Cyrus » Sasl » Version: 2.1.14
    cpe:2.3:a:cyrus:sasl:2.1.14
  • Cyrus » Sasl » Version: 2.1.15
    cpe:2.3:a:cyrus:sasl:2.1.15
  • Cyrus » Sasl » Version: 2.1.16
    cpe:2.3:a:cyrus:sasl:2.1.16
  • Cyrus » Sasl » Version: 2.1.17
    cpe:2.3:a:cyrus:sasl:2.1.17
  • Cyrus » Sasl » Version: 2.1.18
    cpe:2.3:a:cyrus:sasl:2.1.18
  • Cyrus » Sasl » Version: 2.1.18_r1
    cpe:2.3:a:cyrus:sasl:2.1.18_r1
  • Cyrus » Sasl » Version: 2.1.9
    cpe:2.3:a:cyrus:sasl:2.1.9
  • Conectiva » Linux » Version: 10.0
    cpe:2.3:o:conectiva:linux:10.0
  • Conectiva » Linux » Version: 9.0
    cpe:2.3:o:conectiva:linux:9.0


Contact Us

Shodan ® - All rights reserved