RHSA-2022:0666: Important: cyrus-sasl security update
The cyrus-sasl packages contain the Cyrus implementation of Simple Authentication and Security Layer (SASL). SASL is a method for adding authentication support to connection-based protocols.<br>Security Fix(es):<br><li> cyrus-sasl: failure to properly escape SQL input allows an attacker to execute arbitrary SQL commands (CVE-2022-24407)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0666?
The severity of RHSA-2022:0666 is classified as important.
How do I fix RHSA-2022:0666?
To fix RHSA-2022:0666, you should update the cyrus-sasl package to version 2.1.26-24.el7_9 or later.
Which systems are affected by RHSA-2022:0666?
RHSA-2022:0666 affects various packages related to cyrus-sasl on Red Hat Enterprise Linux 7.
What vulnerabilities are addressed in RHSA-2022:0666?
RHSA-2022:0666 addresses a vulnerability related to improper escaping of SQL input in cyrus-sasl.
Is a reboot required after applying the fix for RHSA-2022:0666?
A reboot is not required after applying the fix for RHSA-2022:0666, but it is recommended to restart any services using the updated packages.