CVE-2022-24407 An earlier version of SASL didn't escape the password for a SQL INSERT or UPDATE statement.

CVE-2022-24407 An earlier version of SASL didn't escape the password for a SQL INSERT or UPDATE statement.

This could lead to a remote attacker being able to run arbitrary SQL commands. This issue was resolved by updating plugin code to escape the password. SASL is disabled by default in Cyrus. For more information, see: https://www.sasl- Conference.org/2018/05/13/SASL-CVE-2018-1705. ------------- Cyrus v2.1.28 and later does not have this issue. An update has been applied to the v2.1.28 versions listed above. -------------- NAT-T is a network protocol that provides communication between two NAT devices. It can be used to tunnel any type of data across NAT gateways. NAT-T is not enabled by default in Cyrus. NAT-T can be enabled by changing the NAT-T setting in cyrus.conf. ------------- An update has been applied to the v2.1.28 versions listed above. --------------- An issue has been identified where the bcrypt plugin in Cyrus v2.1.28 through v2.1.38 and v3.0.0 before 3.0.1 does not validate the salt being passed from the client. As a result, an attacker can craft a malformed salt, leading to an infinite loop. This issue was resolved by updating the plugin code to validate the salt. -------------- A denial of service issue was identified in Cyrus v2.1.28 through v2.1.38 and v3.0

Versions Affected

Cyrus v2.1.28 through v2.1.38 and v3.0.0 before 3.0.1
CVE-2022-24407

CVE-2018-1704

An issue was identified where the bcrypt plugin in Cyrus v2.1.28 through v2.1.38 and v3.0.0 before 3.0.1 does not properly validate the salt being passed from the client, leading to an infinite loop when trying to decrypt a password that contains an invalid salt value. ------------- An update has been applied to all versions of Cyrus listed above, resolving this issue -------------- An issue with NAT-T has been identified in Cyrus v2.1.28 through v2.1.38 and v3.0.0 before 3

The 5 Most Common Mistakes Made When Outsourcing SEO
* Keep in mind that there are many different types of SEO strategies and it's important to know what you're getting into before hiring someone else for this job

Cyrus v2.1.28 and later does not have this issue. An update has been applied to the v2.1.28 versions listed above.

An update has been applied to the v2.1.28 versions listed above.

Cyrus v2.1.28 and later does not have these issues

. An update has been applied to the v2.1.28 versions listed above.
Cyrus v2.1.28 and later does not have these issues. An update has been applied to the v2.1.28 versions listed above.

References

Subscribe to CVE.news
Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe