Login
Newsletter
Werbung

Sicherheit: Denial of Service in Cyrus-SASL
Aktuelle Meldungen Distributionen
Name: Denial of Service in Cyrus-SASL
ID: USN-1988-1
Distribution: Ubuntu
Plattformen: Ubuntu 13.04
Datum: Mi, 9. Oktober 2013, 22:48
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4122
Applikationen: Cyrus SASL

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============3494226582577780973==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="3EKRHK7kD4gqwETIT1johe2xTQaqMpoPM"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--3EKRHK7kD4gqwETIT1johe2xTQaqMpoPM
Content-Type: text/plain; charset=UTF-
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1988-1
October 09, 2013

cyrus-sasl2 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04

Summary:

Cyrus SASL could be made to crash if it processed specially crafted input.

Software Description:
- cyrus-sasl2: Cyrus Simple Authentication and Security Layer

Details:

It was discovered that Cyrus SASL incorrectly handled certain invalid
password salts. An attacker could use this issue to cause Cyrus SASL to
crash, resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
libsasl2-2 2.1.25.dfsg1-6ubuntu0.1

After a standard system update you need to reboot your computer to make all
the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1988-1
CVE-2013-4122

Package Information:
https://launchpad.net/ubuntu/+source/cyrus-sasl2/2.1.25.dfsg1-6ubuntu0.1



--3EKRHK7kD4gqwETIT1johe2xTQaqMpoPM
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSVY3ZAAoJEGVp2FWnRL6TTXwP/2fhyBthXQvN4tdxg7cEQgl0
E/994tPgH7qqtCHe97dZ7PtX2vt29scajuueTBtwmZZ7VtKEFlj5yI6GGsZ4ZTHF
jz6BOPdez8ZV7ZWPjbUgLtJFnHadJN+k1EAEbtEMI4BP5gpLJFydZzQjU8xjuxbE
iz1ISJC/0ZR4xRrGFvmgnj+EtqAI1uIlkybLysc+Gvq/Sx77LUnrFkmmtvRiOu1A
Yp0vFL3ukZ3ksZ5/YW+Ca/3B3v6WFYMk6v/f9rO7W3X+1xwKmyyPWLwjal41nwTF
b0wsyYcjt1MLo0rwFs42YK66ZJwzOhmKny08DSw03hCb7E0ozPcRFQ0UEzB6l1Es
LQ/HOIkBM61ESuFje0IkbRijw2nm/EIbcoTwvRhDkPStSEp5AkJfhhaIaF6m1Nuv
eOrOnnO5fWdMcBnjaPAzXsbrVJWyc9FLRPmsR6uEUJ1UpPeLj8wI3JPJ4+JEn06f
bnuoWzPB7W/o8swMJmFXsxfOAzwtElFoKtCaB+avihbAUgah6QRaBnhtJ3UGDt7q
AsWL6KSo1GncA9EppdcUVG8lTq29kaDU8iBHGHQT2S5HFjJI/LlZTlwo+TM9wbcr
q75qfXzRhh9xmgBlma6IyJNOxzwwFBnwPEXJlPoa2pq2BrgyoDNKF0+uesA6ZgG6
vBMbdLNAlnueN5tvGFrx
=3oWc
-----END PGP SIGNATURE-----

--3EKRHK7kD4gqwETIT1johe2xTQaqMpoPM--


--===============3494226582577780973==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============3494226582577780973==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung