cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.
2019-12-19T18:15:12.833
2024-11-21T04:35:37.960
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cyrusimap | cyrus-sasl | < 2.1.28 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Operating System | canonical | ubuntu_linux | 12.04 | Yes |
Operating System | canonical | ubuntu_linux | 14.04 | Yes |
Operating System | canonical | ubuntu_linux | 16.04 | Yes |
Operating System | canonical | ubuntu_linux | 18.04 | Yes |
Operating System | canonical | ubuntu_linux | 19.10 | Yes |
Operating System | fedoraproject | fedora | 31 | Yes |
Operating System | fedoraproject | fedora | 32 | Yes |
Application | redhat | jboss_enterprise_web_server | 2.0.0 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | redhat | enterprise_linux | 5.0 | Yes |
Operating System | redhat | enterprise_linux | 6.0 | Yes |
Operating System | redhat | enterprise_linux | 7.0 | Yes |
Operating System | redhat | enterprise_linux | 8.0 | Yes |
Operating System | redhat | enterprise_linux_eus | 8.4 | Yes |
Operating System | redhat | enterprise_linux_for_ibm_z_systems | 8.0 | Yes |
Operating System | redhat | enterprise_linux_for_ibm_z_systems_eus | 8.4 | Yes |
Operating System | redhat | enterprise_linux_for_power_little_endian | 8.0 | Yes |
Operating System | redhat | enterprise_linux_for_power_little_endian_eus | 8.4 | Yes |
Operating System | redhat | enterprise_linux_server_aus | 8.4 | Yes |
Operating System | redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 8.4 | Yes |
Operating System | redhat | enterprise_linux_server_tus | 8.4 | Yes |
Operating System | redhat | enterprise_linux_server_update_services_for_sap_solutions | 8.4 | Yes |
Operating System | apple | ipados | 13.6 | Yes |
Operating System | apple | iphone_os | 13.6 | Yes |
Operating System | apple | mac_os_x | < 10.13.6 | Yes |
Operating System | apple | mac_os_x | < 10.13.6 | Yes |
Operating System | apple | mac_os_x | < 10.15.6 | Yes |
Operating System | apple | mac_os_x | 10.13.6 | Yes |
Operating System | apple | mac_os_x | 10.13.6 | Yes |
Operating System | apple | mac_os_x | 10.13.6 | Yes |
Operating System | apple | mac_os_x | 10.13.6 | Yes |
Operating System | apple | mac_os_x | 10.13.6 | Yes |
Operating System | apple | mac_os_x | 10.13.6 | Yes |
Operating System | apple | mac_os_x | 10.13.6 | Yes |
Operating System | apple | mac_os_x | 10.13.6 | Yes |
Operating System | apple | mac_os_x | 10.13.6 | Yes |
Operating System | apple | mac_os_x | 10.13.6 | Yes |
Operating System | apple | mac_os_x | 10.13.6 | Yes |
Operating System | apple | mac_os_x | 10.13.6 | Yes |
Operating System | apple | mac_os_x | 10.13.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Application | apache | bookkeeper | 4.12.1 | Yes |
Operating System | centos | centos | 7.0 | No |