CVE-2006-1721
digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in…
Does this matter?
Lower severity and a low EPSS score (2.43%). Track it; it rarely justifies an emergency change on its own.
Description
digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
- EPSS
- 2.43% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- cyrus/sasl
- Source
- cve@mitre.org
References
- ftp://patches.sgi.com/support/free/security/advisories/20070901-01-P.asc
- http://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-sasl&msg=7775
- http://labs.musecurity.com/advisories/MU-200604-01.txtPatch
- http://lists.apple.com/archives/security-announce/2006/Sep/msg00002.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/044992.html
- http://secunia.com/advisories/19618Patch, Vendor Advisory
- http://secunia.com/advisories/19753Vendor Advisory
- http://secunia.com/advisories/19809Vendor Advisory
- http://secunia.com/advisories/19825Vendor Advisory
- http://secunia.com/advisories/19964Vendor Advisory
- http://secunia.com/advisories/20014Vendor Advisory
- http://secunia.com/advisories/22187Vendor Advisory
- http://secunia.com/advisories/26708Vendor Advisory
- http://secunia.com/advisories/26857Vendor Advisory
- http://secunia.com/advisories/27237Vendor Advisory
- http://secunia.com/advisories/30535Vendor Advisory
- http://securitytracker.com/id?1016960
- http://support.avaya.com/elmodocs2/security/ASA-2007-426.htm
- http://www.debian.org/security/2006/dsa-1042
- http://www.gentoo.org/security/en/glsa/glsa-200604-09.xml
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:073
- http://www.novell.com/linux/security/advisories/2006_05_05.html
- http://www.redhat.com/support/errata/RHSA-2007-0795.html
- http://www.redhat.com/support/errata/RHSA-2007-0878.html
- http://www.securityfocus.com/archive/1/493080/100/0/threaded
- http://www.securityfocus.com/bid/17446Patch
- http://www.trustix.org/errata/2006/0024
- http://www.vmware.com/security/advisories/VMSA-2008-0009.html
- http://www.vupen.com/english/advisories/2006/1306Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3852Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.