cyrusimap/cyrus-sasl

cyrusimap/cyrus-sasl

Releases7
Frequency8 months 3 days
Last Release
Stars156

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH6.5 MEDIUM

In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.

7.5 HIGH5 MEDIUM

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.