Description
Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary code.
References (8)
Core 8
Core References
Patch, Vendor Advisory vendor-advisory
x_refsource_suse
http://www.linuxcompatible.org/print42495.html
Vendor Advisory vendor-advisory
x_refsource_mandrake
http://www.mandriva.com/security/advisories?name=MDKSA-2005:054
Patch, Vendor Advisory mailing-list
x_refsource_mlist
http://www.monkey.org/openbsd/archive/ports/0407/msg00265.html
Vendor Advisory x_refsource_confirm
https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c?rev=1.171&content-type=text/x-cvsweb-markup
Vendor Advisory x_refsource_confirm
https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c.diff?r1=1.170&r2=1.171
Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/11347
Patch, Vendor Advisory vendor-advisory
x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200410-05.xml
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17642
Scores
EPSS
0.0476
EPSS Percentile
89.6%
Details
Status
published
Products (50)
apple/mac_os_x
10.0
apple/mac_os_x
10.0.1
apple/mac_os_x
10.0.2
apple/mac_os_x
10.0.3
apple/mac_os_x
10.0.4
apple/mac_os_x
10.1
apple/mac_os_x
10.1.1
apple/mac_os_x
10.1.2
apple/mac_os_x
10.1.3
apple/mac_os_x
10.1.4
... and 40 more
Published
Oct 07, 2004
Tracked Since
Feb 18, 2026