CVE-2004-0884: High severity cyrus sasl vulnerability
The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASLPATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASLPATH to point to malicious programs.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0884?
CVE-2004-0884 has been classified as a high severity vulnerability due to the potential for local users to execute arbitrary code.
How do I fix CVE-2004-0884?
To fix CVE-2004-0884, upgrade to a patched version of the Cyrus-SASL library, specifically versions 2.1.19 or later.
What systems are affected by CVE-2004-0884?
CVE-2004-0884 affects multiple versions of the Cyrus-SASL library as well as certain Conectiva Linux distributions including versions 9.0 and 10.0.
Can CVE-2004-0884 be exploited remotely?
CVE-2004-0884 cannot be exploited remotely; it requires local access to the affected system.
What is the impact of CVE-2004-0884 on system security?
The impact of CVE-2004-0884 on system security includes the risk of unauthorized code execution, potentially compromising system integrity.