Logo
componentcyrus-sasl
Name
cyrus-sasl
Version
2.1.28
Type
library
Description
Generic client/server library for SASL authentication
Licenses
BSD-4-Clause
PURL
-
CPE
cpe:2.3:*:*:cyrus-sasl:2.1.28:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
2.1.28
scarthgap
2.1.28

Patches#


#
Title
Author
Resolve
1
sample: Rename dprintf to cyrus_dprintf
Khem Raj <raj.khem@gmail.com>
2
Fix #587
Changqing Li <changqing.li@windriver.com>
CVE-2019-19906
3
Fix hardcoded libdir.
"Roy.Li" <rongqing.li@windriver.com>
4
CVE-2022-24407
Hitendra Prajapati <hprajapati@mvista.com>
CVE-2022-24407
5
cyrus-sasl: Add patches from Debian to fix linking
Fabian Fagerholm <fabbe@debian.org>
6
Avoid to call AC_TRY_RUN
"Roy.Li" <rongqing.li@windriver.com>

Vulnerabilities#


Name
Analysis
Description
Patched
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
Patched
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.