CVE Vulnerabilities

CVE-2005-0373

Published: Oct 07, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary code.

Affected Software

NameVendorStart VersionEnd Version
SaslCyrus1.5.24 (including)1.5.24 (including)
SaslCyrus1.5.27 (including)1.5.27 (including)
SaslCyrus1.5.28 (including)1.5.28 (including)
SaslCyrus2.1.9 (including)2.1.9 (including)
SaslCyrus2.1.10 (including)2.1.10 (including)
SaslCyrus2.1.11 (including)2.1.11 (including)
SaslCyrus2.1.12 (including)2.1.12 (including)
SaslCyrus2.1.13 (including)2.1.13 (including)
SaslCyrus2.1.14 (including)2.1.14 (including)
SaslCyrus2.1.15 (including)2.1.15 (including)
SaslCyrus2.1.16 (including)2.1.16 (including)
SaslCyrus2.1.17 (including)2.1.17 (including)
SaslCyrus2.1.18 (including)2.1.18 (including)
SaslCyrus2.1.18_r1 (including)2.1.18_r1 (including)
OpenpkgOpenpkg2.1 (including)2.1 (including)
OpenpkgOpenpkg2.2 (including)2.2 (including)
Suse_cvsupSuse16.1h_36.i586 (including)16.1h_36.i586 (including)
LinuxConectiva9.0 (including)9.0 (including)
LinuxConectiva10.0 (including)10.0 (including)

References