Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-19906

Опубликовано: 19 дек. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.

РелизСтатусПримечание
bionic

released

2.1.27~101-g0780600+dfsg-3ubuntu2.1
devel

released

2.1.17+dfsg-2
disco

ignored

end of life
eoan

released

2.1.27+dfsg-1ubuntu0.1
esm-infra-legacy/trusty

released

2.1.25.dfsg1-17ubuntu0.1~esm1
esm-infra/bionic

released

2.1.27~101-g0780600+dfsg-3ubuntu2.1
esm-infra/xenial

released

2.1.26.dfsg1-14ubuntu0.2
precise/esm

not-affected

2.1.25.dfsg1-3ubuntu0.2
trusty

ignored

end of standard support
trusty/esm

released

2.1.25.dfsg1-17ubuntu0.1~esm1

Показывать по

EPSS

Процентиль: 60%
0.00396
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
около 6 лет назад

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.

CVSS3: 7.5
nvd
почти 6 лет назад

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.

CVSS3: 7.5
msrc
больше 5 лет назад

Описание отсутствует

CVSS3: 7.5
debian
почти 6 лет назад

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading ...

suse-cvrf
около 3 лет назад

Security update for cyrus-sasl

EPSS

Процентиль: 60%
0.00396
Низкий

5 Medium

CVSS2

7.5 High

CVSS3