DESCRIPTION
SASL[1] is the Simple Authentication and Security Layer, a method for
adding authentication support to connection-based protocols.
A vulnerability[2] has been discovered in the Cyrus implementation of
the SASL library. The library honors the environment variable
SASL_PATH blindly, which allows a local attacker to link against a
malicious library to run arbitrary code with the privileges of a
setuid or setgid application.
SOLUTION
It is recommended that all sasl2 users upgrade their packages.
IMPORTANT: If you are using Conectiva Linux 9, it is important to
restart saslauthd daemon after upgrading the packages, in order to
really fix the vulnerability.