CVE-2000-0956: Medium severity Carnegie Mellon University Cyrus-sasl vulnerability
Published Dec 19, 2000
·Updated
cyrus-sasl before 1.5.24 in Red Hat Linux 7.0 does not properly verify the authorization for a local user, which could allow the users to bypass specified access restrictions.
Affected Software
1 affected component
Carnegie Mellon University Cyrus-sasl=1.5.24
Remediation
Patch Available
Patch Available
Event History
Dec 19, 2000
CVE Published
05:00 AM
Jan 22, 2001
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0956?
CVE-2000-0956 is considered a medium severity vulnerability due to its potential to allow unauthorized access for local users.
2
How do I fix CVE-2000-0956?
To fix CVE-2000-0956, upgrade to Cyrus SASL version 1.5.24 or later, which addresses the authorization verification issue.
3
What systems are affected by CVE-2000-0956?
CVE-2000-0956 affects Cyrus SASL versions prior to 1.5.24 on Red Hat Linux 7.0.
4
Who can exploit CVE-2000-0956?
Any local user on the affected system can exploit CVE-2000-0956 to bypass specified access restrictions.
5
What type of vulnerability is CVE-2000-0956?
CVE-2000-0956 is a local privilege escalation vulnerability related to improper authorization checks in Cyrus SASL.