2 verifications about Cyrus SASL Cyrus SASL ×
“Debian Security Advisory DSA-180-1 describes a Cyrus SASL username buffer overflow vulnerability.”
Official Debian records show that DSA-180-1 is a cyrus-sasl security advisory about buffer overflow vulnerabilities, specifically including overflow risk in username-string handling. That matches the claim closely. The main caveat is only that readers should not confuse this 2003 advisory with later, separate Cyrus SASL vulnerabilities.
“Cyrus SASL library versions 2.1.9 and earlier have a buffer overflow vulnerability that can be triggered by long inputs during user name canonicalization.”
The evidence strongly supports this as the long-documented Cyrus SASL flaw CVE-2002-1347. Multiple independent advisories state that Cyrus SASL 2.1.9 and earlier are vulnerable to a buffer overflow triggered by long usernames during canonicalization. Conflicting references point to a separate 2026 MongoDB C Driver integration bug, not the library vulnerability described here.