Cyrus SASL 2.1.23 Released
Ken Murchison <[email protected]> Thu, 14 May 2009 13:05:34 -0400
| Newsgroups | gmane.mail.imap.cyrus.announce |
|---|---|
| Organization | Carnegie Mellon University |
| Message-ID | <4A0C4F5E.8080901__19149.2073740394$1242321017$gmane$org@andrew.cmu.edu> |
I'd like to announce the release of Cyrus SASL 2.1.23 on ftp.andrew.cmu.edu. This version includes a fix for a potential buffer overflow in sasl_encode64() (see http://www.kb.cert.org/vuls/id/238019), otherwise it is identical to 2.1.22. Please note that while this fixes vulnerable code, non-vulnerable code may break if the buffer passed to sasl_encode64() is the exact size of the encoded data and doesn't include space for the trailing NUL. Please send any feedback either to [email protected] (public list) or to [email protected]. Download at: ftp://ftp.andrew.cmu.edu/pub/cyrus-mail/cyrus-sasl-2.1.23.tar.gz -- Kenneth Murchison Systems Programmer Carnegie Mellon University