Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-19906

Опубликовано: 28 нояб. 2019
Источник: redhat
CVSS3: 7.5

Описание

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5cyrus-saslOut of support scope
Red Hat Enterprise Linux 6cyrus-saslOut of support scope
Red Hat Enterprise Linux 7cyrus-saslWill not fix
Red Hat JBoss Enterprise Web Server 2cyrus-saslOut of support scope
Red Hat Enterprise Linux 8cyrus-saslFixedRHSA-2020:449704.11.2020
Red Hat Enterprise Linux 8cyrus-saslFixedRHSA-2020:449704.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1791854cyrus-sasl: denial of service in _sasl_add_string function

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.

CVSS3: 7.5
nvd
почти 6 лет назад

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.

CVSS3: 7.5
msrc
больше 5 лет назад

Описание отсутствует

CVSS3: 7.5
debian
почти 6 лет назад

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading ...

suse-cvrf
около 3 лет назад

Security update for cyrus-sasl

7.5 High

CVSS3