Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-48829

Опубликовано: 24 мая 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.

РелизСтатусПримечание
devel

not-affected

2.2.4-1
esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-infra-legacy/trusty

needs-triage

jammy

needs-triage

noble

released

2.2.1-1willsync1ubuntu0.1
questing

released

2.2.2-2ubuntu1.1
resolute

released

2.2.2-4ubuntu1.1

Показывать по

EPSS

Процентиль: 37%
0.00455
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
3 месяца назад

In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.

CVSS3: 7.5
debian
3 месяца назад

In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference af ...

suse-cvrf
около 2 месяцев назад

Security update for gsasl

CVSS3: 7.5
github
3 месяца назад

In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.

EPSS

Процентиль: 37%
0.00455
Низкий

7.5 High

CVSS3