7.2

CVE-2004-0884

The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASL_PATH to point to malicious programs.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CyrusSasl Version1.5.24
CyrusSasl Version1.5.27
CyrusSasl Version1.5.28
CyrusSasl Version2.1.9
CyrusSasl Version2.1.10
CyrusSasl Version2.1.11
CyrusSasl Version2.1.12
CyrusSasl Version2.1.13
CyrusSasl Version2.1.14
CyrusSasl Version2.1.15
CyrusSasl Version2.1.16
CyrusSasl Version2.1.17
CyrusSasl Version2.1.18
CyrusSasl Version2.1.18_r1
ConectivaLinux Version9.0
ConectivaLinux Version10.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.155
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C