SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-1721

digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in…

LOW 2.6EPSS 2.43%

Does this matter?

Lower severity and a low EPSS score (2.43%). Track it; it rarely justifies an emergency change on its own.

Description

digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.

CVSS 2.0
2.6 LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
EPSS
2.43% probability · 83th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
cyrus/sasl
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.