Bug 190694

Summary: CVE-2006-1721 cyrus-sasl digest-md5 DoS
Product: [Retired] Fedora Legacy Reporter: David Eisenstein <deisenst>
Component: cyrus-saslAssignee: Fedora Legacy Bugs <bugs>
Status: CLOSED CANTFIX QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: fc3CC: mattdm
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
URL: http://labs.musecurity.com/advisories/MU-200604-01.txt
Whiteboard: impact=moderate, LEGACY, rh73, rh90, 1, 2, 3, NEEDSWORK
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2007-04-10 19:17:28 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 189814    
Bug Blocks:    

Description David Eisenstein 2006-05-04 15:16:26 UTC
+++ This bug was initially created as a clone of Bug #189814 +++

cyrus-sasl digest-md5 DoS

A DoS during SASL authentication digest-md5 negotiation could crash an
applications authenticating using the digest-md5 feature of
cyrus-sasl.

This issue was fixed upstream in 2.1.21.

An advisory regarding this issue was published here:
http://labs.musecurity.com/advisories/MU-200604-01.txt

The note from upstream verifying the isue was fixed in 2.1.21 is here:
http://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-sasl&msg=7775


This issue also affects RHEL3

Comment 1 David Eisenstein 2006-05-04 15:24:07 UTC
This issue affects RHL9, FC1, FC2 and FC3; and may also affect RHL 7.3,
though RHL 7.3 uses a much older version of cyrus-sasl.  We will have to look
into it.


Comment 2 Matthew Miller 2007-04-10 19:17:28 UTC
Fedora Core 3 is now completely unmaintained. These bugs can't be fixed in that
version. If the issue still persists in current Fedora Core, please reopen.
Thank you, and sorry about this.