CVE-2002-1347
9.8
CRITICAL · CVSS 3.1 · EPSS 7.1% (pctl 94)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 7.08% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-131 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2002-12-18 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| apple | mac os x |
| apple | mac os x server |
| cyrusimap | cyrus sasl |
References
- http://archives.neohapsis.com/archives/linux/suse/2002-q4/1275.html
- http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000557
- http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html
- http://marc.info/?l=bugtraq&m=103946297703402&w=2
- http://www.debian.org/security/2002/dsa-215
- http://www.redhat.com/support/errata/RHSA-2002-283.html
- http://www.securityfocus.com/advisories/4826
- http://www.securityfocus.com/bid/6347
- http://www.securityfocus.com/bid/6348
- http://www.securityfocus.com/bid/6349
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10810
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10811
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10812
- http://archives.neohapsis.com/archives/linux/suse/2002-q4/1275.html
- http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000557
- http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html
- http://marc.info/?l=bugtraq&m=103946297703402&w=2
- http://www.debian.org/security/2002/dsa-215
- http://www.redhat.com/support/errata/RHSA-2002-283.html
- http://www.securityfocus.com/advisories/4826
→ the Explorer · watch your stack · NVD