CVE-2009-0688
Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via strings that are used as input to the sasl_encode64 function in lib/saslutil.c.
Date published : 2009-05-15
http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html