← Back

CVE-2013-4122

nvd nist
Published: Oct 27, 2013Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cyrus SASL 2.1.23, 2.1.26, and earlier does not properly handle when a NULL value is returned upon an error by the crypt function as implemented in glibc 2.17 and later, which allows remote attackers to cause a denial of service (thread crash and consumption) via (1) an invalid salt or, when FIPS-140 is enabled, a (2) DES or (3) MD5 encrypted password, which triggers a NULL pointer dereference.

Affected (9)

Products: Cmu: Cyrus Sasl
1 product
Cyrus Sasl
Configuration A
9 vulnerable · 24 platform
Vulnerable SoftwareAffected Versions
Cmu
Up to 2.1.26
Version 1.5.28
Version 2.1.19
Version 2.1.20
Version 2.1.21
Version 2.1.22
Version 2.1.23
Version 2.1.24
Version 2.1.25
Running on/withPlatform Versions
Gnu
Glibc
Version 2.17
Gnu
Glibc
Version 2.18
Gnu
Glibc
Version 2.2.1
Gnu
Glibc
Version 2.2.2
Gnu
Glibc
Version 2.2.3
Gnu
Glibc
Version 2.2.4
Gnu
Glibc
Version 2.2.5
Gnu
Glibc
Version 2.2
Gnu
Glibc
Version 2.3.10
Gnu
Glibc
Version 2.3.1
Gnu
Glibc
Version 2.3.2
Gnu
Glibc
Version 2.3.3
Gnu
Glibc
Version 2.3.4
Gnu
Glibc
Version 2.3.5
Gnu
Glibc
Version 2.3.6
Gnu
Glibc
Version 2.3
Gnu
Glibc
Version 2.4
Gnu
Glibc
Version 2.5.1
Gnu
Glibc
Version 2.5
Gnu
Glibc
Version 2.6.1
Gnu
Glibc
Version 2.6
Gnu
Glibc
Version 2.7
Gnu
Glibc
Version 2.8
Gnu
Glibc
Version 2.9

Related CWEs

References (18)

Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.