Wednesday, October 9, 2013

[USN-1988-1] Cyrus SASL vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSVY3ZAAoJEGVp2FWnRL6TTXwP/2fhyBthXQvN4tdxg7cEQgl0
E/994tPgH7qqtCHe97dZ7PtX2vt29scajuueTBtwmZZ7VtKEFlj5yI6GGsZ4ZTHF
jz6BOPdez8ZV7ZWPjbUgLtJFnHadJN+k1EAEbtEMI4BP5gpLJFydZzQjU8xjuxbE
iz1ISJC/0ZR4xRrGFvmgnj+EtqAI1uIlkybLysc+Gvq/Sx77LUnrFkmmtvRiOu1A
Yp0vFL3ukZ3ksZ5/YW+Ca/3B3v6WFYMk6v/f9rO7W3X+1xwKmyyPWLwjal41nwTF
b0wsyYcjt1MLo0rwFs42YK66ZJwzOhmKny08DSw03hCb7E0ozPcRFQ0UEzB6l1Es
LQ/HOIkBM61ESuFje0IkbRijw2nm/EIbcoTwvRhDkPStSEp5AkJfhhaIaF6m1Nuv
eOrOnnO5fWdMcBnjaPAzXsbrVJWyc9FLRPmsR6uEUJ1UpPeLj8wI3JPJ4+JEn06f
bnuoWzPB7W/o8swMJmFXsxfOAzwtElFoKtCaB+avihbAUgah6QRaBnhtJ3UGDt7q
AsWL6KSo1GncA9EppdcUVG8lTq29kaDU8iBHGHQT2S5HFjJI/LlZTlwo+TM9wbcr
q75qfXzRhh9xmgBlma6IyJNOxzwwFBnwPEXJlPoa2pq2BrgyoDNKF0+uesA6ZgG6
vBMbdLNAlnueN5tvGFrx
=3oWc
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1988-1
October 09, 2013

cyrus-sasl2 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04

Summary:

Cyrus SASL could be made to crash if it processed specially crafted input.

Software Description:
- cyrus-sasl2: Cyrus Simple Authentication and Security Layer

Details:

It was discovered that Cyrus SASL incorrectly handled certain invalid
password salts. An attacker could use this issue to cause Cyrus SASL to
crash, resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
libsasl2-2 2.1.25.dfsg1-6ubuntu0.1

After a standard system update you need to reboot your computer to make all
the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1988-1
CVE-2013-4122

Package Information:
https://launchpad.net/ubuntu/+source/cyrus-sasl2/2.1.25.dfsg1-6ubuntu0.1

No comments:

Post a Comment