HIGH · 7.5

CVE-2005-0373

Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to e...

Vulnerability Description

Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary code.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
CyrusSasl1.5.24
OpenpkgOpenpkg2.1
SuseSuse Cvsup16.1h_36.i586
ConectivaLinux9.0
AppleMac Os X10.0
AppleMac Os X Server10.0
RedhatFedora Corecore_1.0
SuseSuse Linux1.0

References

FAQ

What is CVE-2005-0373?

CVE-2005-0373 is a vulnerability with a CVSS score of 7.5 (HIGH). Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to e...

How severe is CVE-2005-0373?

CVE-2005-0373 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-0373?

Check the references section above for vendor advisories and patch information. Affected products include: Cyrus Sasl, Openpkg Openpkg, Suse Suse Cvsup, Conectiva Linux, Apple Mac Os X.