漏洞信息详情
Cyrus Sasl SQL注入漏洞
漏洞简介
Cyrus Sasl是The Cyrus Team团队的一种简单身份验证。使应用程序开发人员可以轻松地将身份验证机制以通用方式集成到应用程序中。
Cyrus SASL 存在SQL注入漏洞,该漏洞源于 Cyrus SASL SQL 插件错误地处理了 SQL 输入。远程攻击者可以利用此问题执行任意 SQL 命令。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://ubuntu.com/security/notices/USN-5301-1
参考网址
来源:DEBIAN
链接:https://www.debian.org/security/2022/dsa-5087
来源:CONFIRM
链接:https://github.com/cyrusimap/cyrus-sasl/blob/fdcd13ceaef8de684dc69008011fa865c5b4a3ac/docsrc/sasl/release-notes/2.1/index.rst
来源:MISC
链接:https://www.cyrusimap.org/sasl/sasl/release-notes/2.1/index.html#new-in-2-1-28
来源:MLIST
链接:http://www.openwall.com/lists/oss-security/2022/02/23/4
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2022022410
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2022.0794
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/166192/Red-Hat-Security-Advisory-2022-0731-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/166143/Red-Hat-Security-Advisory-2022-0668-01.html
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2022-24407
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2022022423
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/166121/Ubuntu-Security-Notice-USN-5301-1.html
来源:cxsecurity.com
链接:https://cxsecurity.com/cveshow/CVE-2022-24407/
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Cyrus-SASL-SQL-injection-via-SQL-Plugin-37632
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/166134/Red-Hat-Security-Advisory-2022-0658-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2022.0839
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2022022529
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2022030224
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2022.0903
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2022030323
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2022.0812
受影响实体
暂无
补丁
- Cyrus Sasl SQL注入漏洞的修复措施<!--2022-2-22-->
还没有评论,来说两句吧...