Oval Definition:oval:org.mitre.oval:tst:30998
Comment:cyrus-sasl-plain is earlier than 0:2.1.15-10
Type:rpminfo_testNamespace:linux
Check_Existence:at_least_one_existsCheck:at least one
State Operator:AND
References
Object:oval:org.mitre.oval:obj:14379
State:oval:org.mitre.oval:ste:9418
Referencing Definitions
Definition IDClassTitleLast Modified
oval:org.mitre.oval:def:11678
V
The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASL_PATH to point to malicious programs.
2013-04-29
BACK