<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:cyrus_sasl_project:cyrus_sasl:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3acyrus_sasl_projectcyrus_sasl/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 20:45:26 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3acyrus_sasl_projectcyrus_sasl/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Heap-based Buffer Overflow in Cyrus SASL DIGEST-MD5 Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-cyrus-sasl-overflow/</link><pubDate>Wed, 07 Oct 2026 20:45:26 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cyrus-sasl-overflow/</guid><description>A heap-based buffer overflow in the Cyrus SASL DIGEST-MD5 plugin, tracked as CVE-2026-107161, allows remote malicious servers to cause memory corruption in client applications.</description><content:encoded><![CDATA[<p>CVE-2026-107161 identifies a critical heap-based buffer overflow vulnerability within the Cyrus SASL library, specifically affecting the DIGEST-MD5 plugin. The flaw resides in the add_to_challenge() function, which incorrectly calculates the required buffer size for challenge/response fields. The calculation occurs prior to the application of DIGEST-MD5 quoting, which escapes special characters and expands the string length. Consequently, the library allocates an insufficient buffer, which is subsequently passed to strcat(), resulting in a heap-based out-of-bounds write.</p>
<p>The vulnerability is triggered when a client application, utilizing the affected version of Cyrus SASL, connects to a malicious or compromised server that sends a crafted challenge field (e.g., realm or nonce). The resulting memory corruption typically causes the client application to crash, though the primitive may support arbitrary code execution in specific environments. Because the vulnerability exists within the client-side parsing logic, any application linking against the vulnerable version of Cyrus SASL for authentication is potentially at risk.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability leads to a denial of service through application crashes. Given the nature of the heap-based buffer overflow, there is a risk of arbitrary code execution, which could allow an attacker to compromise the host system running the client-side software. This vulnerability affects any environment using Cyrus SASL for authentication, including enterprise mail servers, directory services, and various network client tools.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Detection and mitigation should focus on upgrading the library and monitoring for application instability.</p>
<ul>
<li>Upgrade the Cyrus SASL library to the patched version once released by the vendor or package maintainer.</li>
<li>Monitor application logs and system event logs (such as Windows Event Viewer or Linux systemd journal) for frequent crash dumps (SIGSEGV or access violations) originating from services utilizing Cyrus SASL.</li>
<li>Audit client-side network connections to verify that they are connecting only to known-trusted and authenticated servers to mitigate the risk of a malicious server triggering the flaw.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>memory-corruption</category></item></channel></rss>