[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

cyrus-sasl: Off by one in _sasl_add_string function (CVE-2019-19906)

ID: oval:org.secpod.oval:def:1801648Date: (C)2019-12-30   (M)2023-11-10
Class: PATCHFamily: unix




Cyrus-sasl 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.

Platform:
Alpine Linux 3.10
Alpine Linux 3.11
Alpine Linux 3.8
Alpine Linux 3.9
Product:
cyrus-sasl
Reference:
11079
CVE-2019-19906
CVE    1
CVE-2019-19906

© SecPod Technologies