Comment 2Huzaifa S. Sidhpurwala
2020-02-18 04:50:58 UTC
Analysis:
This is essentially an off-by-one, causing a heap OOB read by 1 byte. Arbitrary code execution seems difficult because of the assertions in place, so all it can do is cause remote DoS of the SASL service. Currently there is no upstream patch for this.
Comment 3Huzaifa S. Sidhpurwala
2020-02-18 04:54:01 UTC
Created cyrus-sasl tracking bugs for this issue:
Affects: fedora-all [bug 1804034]
Comment 5Fedora Update System
2020-04-01 00:16:36 UTC
FEDORA-2020-51d591d035 has been pushed to the Fedora 32 stable repository.
If problem still persists, please make note of it in this bug report.
Comment 6Fedora Update System
2020-04-01 16:31:45 UTC
FEDORA-2020-51d591d035 has been pushed to the Fedora 32 stable repository.
If problem still persists, please make note of it in this bug report.