Skip to content
Rota Nacional

Cyber ·

Unanswered public security issues in Cyrus SASL

An oss-sec post dated 9 October reports publicly disclosed Cyrus SASL security problems with no maintainer response and no new release since 2022.

A post by Alan Coopersmith on the oss-sec list, dated 9 October, reports several publicly disclosed security problems in the Cyrus SASL project with no response from maintainers. According to the text, former maintainers say they are no longer involved. The last release dates from 2022, and the only commits in the past year were documentation updates recording cyrus-imapd releases. The advisory lists open problems, including memory leaks in functions related to authentication secrets. The full list is not in the excerpt received, which is a machine translation and may contain inaccuracies. Relevance: organizations that use Cyrus SASL as an authentication component should treat this also as a maintenance risk, not only as a single flaw. It is worth inventorying where the library appears, following operating system vendor advisories, and assessing isolation or replacement. Rota Nacional does not patch this library and does not solve the engineering problem described.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free