Vulnerability Description
cyrus-sasl before 1.5.24 in Red Hat Linux 7.0 does not properly verify the authorization for a local user, which could allow the users to bypass specified access restrictions.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Carnegie Mellon University | Cyrus-Sasl | 1.5.24 |
References
- http://www.redhat.com/support/errata/RHSA-2000-094.htmlPatchVendor Advisory
- http://www.securityfocus.com/bid/1875PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5427
- http://www.redhat.com/support/errata/RHSA-2000-094.htmlPatchVendor Advisory
- http://www.securityfocus.com/bid/1875PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5427
FAQ
What is CVE-2000-0956?
CVE-2000-0956 is a vulnerability with a CVSS score of 4.6 (MEDIUM). cyrus-sasl before 1.5.24 in Red Hat Linux 7.0 does not properly verify the authorization for a local user, which could allow the users to bypass specified access restrictions.
How severe is CVE-2000-0956?
CVE-2000-0956 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2000-0956?
Check the references section above for vendor advisories and patch information. Affected products include: Carnegie Mellon University Cyrus-Sasl.