CVE-2009-0688

UnknownEPSS 8.21%

Last modified

CVE-2009-0688 is a vulnerability of currently unknown severity. Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via strings that are used as input to the sasl_encode64 function in lib/saslutil.c.. EPSS estimates a 8.21% chance of exploitation in the next 30 days.

Description

Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via strings that are used as input to the sasl_encode64 function in lib/saslutil.c.

Metrics

EPSS Probability
8.21%

94.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Carnegie Mellon UniversityCyrus-Sasl<= 2.1.22
Carnegie Mellon UniversityCyrus-Sasl1.4.1
Carnegie Mellon UniversityCyrus-Sasl1.5.0
Carnegie Mellon UniversityCyrus-Sasl1.5.2
Carnegie Mellon UniversityCyrus-Sasl1.5.3
Carnegie Mellon UniversityCyrus-Sasl1.5.5
Carnegie Mellon UniversityCyrus-Sasl1.5.10
Carnegie Mellon UniversityCyrus-Sasl1.5.11
Carnegie Mellon UniversityCyrus-Sasl1.5.13
Carnegie Mellon UniversityCyrus-Sasl1.5.15
Carnegie Mellon UniversityCyrus-Sasl1.5.16
Carnegie Mellon UniversityCyrus-Sasl1.5.20
Carnegie Mellon UniversityCyrus-Sasl1.5.21
Carnegie Mellon UniversityCyrus-Sasl1.5.22
Carnegie Mellon UniversityCyrus-Sasl1.5.23
Carnegie Mellon UniversityCyrus-Sasl1.5.24
Carnegie Mellon UniversityCyrus-Sasl1.5.26
Carnegie Mellon UniversityCyrus-Sasl1.5.27
Carnegie Mellon UniversityCyrus-Sasl1.5.28
Carnegie Mellon UniversityCyrus-Sasl2.0.0
Carnegie Mellon UniversityCyrus-Sasl2.0.1
Carnegie Mellon UniversityCyrus-Sasl2.0.2
Carnegie Mellon UniversityCyrus-Sasl2.0.3
Carnegie Mellon UniversityCyrus-Sasl2.0.4
Carnegie Mellon UniversityCyrus-Sasl2.0.5
Carnegie Mellon UniversityCyrus-Sasl2.1.0
Carnegie Mellon UniversityCyrus-Sasl2.1.1
Carnegie Mellon UniversityCyrus-Sasl2.1.2
Carnegie Mellon UniversityCyrus-Sasl2.1.3
Carnegie Mellon UniversityCyrus-Sasl2.1.5
Carnegie Mellon UniversityCyrus-Sasl2.1.6
Carnegie Mellon UniversityCyrus-Sasl2.1.7
Carnegie Mellon UniversityCyrus-Sasl2.1.8
Carnegie Mellon UniversityCyrus-Sasl2.1.9
Carnegie Mellon UniversityCyrus-Sasl2.1.10
Carnegie Mellon UniversityCyrus-Sasl2.1.11
Carnegie Mellon UniversityCyrus-Sasl2.1.12
Carnegie Mellon UniversityCyrus-Sasl2.1.13
Carnegie Mellon UniversityCyrus-Sasl2.1.14
Carnegie Mellon UniversityCyrus-Sasl2.1.15
Carnegie Mellon UniversityCyrus-Sasl2.1.16
Carnegie Mellon UniversityCyrus-Sasl2.1.17
Carnegie Mellon UniversityCyrus-Sasl2.1.18
Carnegie Mellon UniversityCyrus-Sasl2.1.19
Carnegie Mellon UniversityCyrus-Sasl2.1.20
Carnegie Mellon UniversityCyrus-Sasl2.1.21

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2009-0688?
Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via strings that are used as input to the sasl_encode64 function in lib/saslutil.c.
How severe is CVE-2009-0688?
Severity scoring for CVE-2009-0688 is pending analysis. The EPSS model estimates a 8.21% probability of exploitation in the next 30 days.
How do I fix CVE-2009-0688?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2009-0688?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST