VDB
CVE-2005-0373
CVE-2005-0373
PUBLISHED
CVSS 7.5 HIGH
Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary code.
EPSS 3.92% · 89.3th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
3.92%
89.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | mac_os_x_server | 10.2.1, 10.3, 10.2.3 |
| conectiva | linux | 10.0, 9.0 |
| redhat | fedora_core | core_1.0 |
| suse | suse_linux | 9.2, 1.0, 8.0 |
| apple | mac_os_x | 10.3.5, 10.3.8, 10.3.7 |
| suse | suse_cvsup | 16.1h_36.i586 |
| cyrus | sasl | 2.1.13, 2.1.15, 2.1.16 |
| n/a | n/a | n/a |
| openpkg | openpkg | 2.2, 2.1 |
Timeline
- Oct 7, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- MDKSA-2005:054 vendor-advisory
- 11347 vdb
- cyrus-sasl-digestmda5-bo(17642) vdb
- https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c?rev=1.171&content-type=text/x-cvsweb-markup url
- GLSA-200410-05 vendor-advisory
- http://www.linuxcompatible.org/print42495.html patch
- http://www.monkey.org/openbsd/archive/ports/0407/msg00265.html patch
- https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c.diff?r1=1.170&r2=1.171 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2005-0373 advisory