Description
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.
Published: 2019-12-19
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-2044-1 cyrus-sasl2 security update
Debian DSA Debian DSA DSA-4591-1 cyrus-sasl2 security update
EUVD EUVD EUVD-2019-9498 cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.
Ubuntu USN Ubuntu USN USN-4256-1 Cyrus SASL vulnerability
History

No history.

Subscriptions

Apache Bookkeeper
Apple Ipados Iphone Os Mac Os X
Canonical Ubuntu Linux
Centos Centos
Cyrusimap Cyrus-sasl
Debian Debian Linux
Fedoraproject Fedora
Redhat Enterprise Linux Enterprise Linux Eus Enterprise Linux For Ibm Z Systems Enterprise Linux For Ibm Z Systems Eus Enterprise Linux For Power Little Endian Enterprise Linux For Power Little Endian Eus Enterprise Linux Server Aus Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Enterprise Linux Server Tus Enterprise Linux Server Update Services For Sap Solutions Jboss Enterprise Web Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T02:32:09.289Z

Reserved: 2019-12-19T00:00:00.000Z

Link: CVE-2019-19906

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-12-19T18:15:12.833

Modified: 2024-11-21T04:35:37.960

Link: CVE-2019-19906

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-11-28T00:00:00Z

Links: CVE-2019-19906 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses