CVE-2006-1721
published 2006-04-11CVE-2006-1721: digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote…
PriorityP418low2.6CVSS 2.0
AVNACHAuNCNINAP
EPSS
2.43%
83.1th percentile
digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cyrus | sasl | — | — |
| cyrus | sasl | — | — |
| cyrus | sasl | — | — |
| cyrus | sasl | — | — |
| cyrus | sasl | — | — |
| debian | cyrus-sasl2 | < cyrus-sasl2 2.1.19.dfsg1-0.2 (bookworm) | cyrus-sasl2 2.1.19.dfsg1-0.2 (bookworm) |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_workstation | — | — |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
osv2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues
vendor_vmware·2008-06-04·CVSS 2.6
CVE-2006-1721 [LOW] Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues
VMSA-2008-0009: Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues
Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues VMware Security Advisory VMware Security AdvisoryAdvisory ID: VMware Security AdvisorySynopsis: Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues VMware Security AdvisoryIssue date: VMware Security AdvisoryUpdated on:
CVEs: CVE-2006-1721, CVE-2007-4772, CVE-2007-5378, CVE-2007-5671, CVE-2008-0062, CVE-2008-0063, CVE-2008-0553, CVE-2008-0888, CVE-2
Ubuntu
cyrus-sasl2 vulnerability
vendor_ubuntu·2006-04-24
CVE-2006-1721 cyrus-sasl2 vulnerability
Title: cyrus-sasl2 vulnerability
Summary: cyrus-sasl2 vulnerability
A Denial of Service vulnerability has been discovered in the SASL
authentication library when using the DIGEST-MD5 plugin. By sending a
specially crafted realm name, a malicious SASL server could exploit
this to crash the application that uses SASL.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2006-1721: cyrus-sasl2 - digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) lib...
vendor_debian·2006·CVSS 2.6
CVE-2006-1721 [LOW] CVE-2006-1721: cyrus-sasl2 - digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) lib...
digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.
Scope: local
bookworm: resolved (fixed in 2.1.19.dfsg1-0.2)
bullseye: resolved (fixed in 2.1.19.dfsg1-0.2)
forky: resolved (fixed in 2.1.19.dfsg1-0.2)
sid: resolved (fixed in 2.1.19.dfsg1-0.2)
trixie: resolved (fixed in 2.1.19.dfsg1-0.2)
Red Hat
cyrus-sasl digest-md5 DoS
vendor_redhat·2005-05-15·CVSS 2.6
CVE-2006-1721 [LOW] cyrus-sasl digest-md5 DoS
cyrus-sasl digest-md5 DoS
digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.
GHSA
GHSA-x5mm-w7g6-r6fq: digestmd5
ghsa_unreviewed·2022-05-03
CVE-2006-1721 [LOW] CWE-20 GHSA-x5mm-w7g6-r6fq: digestmd5
digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.
OSV
CVE-2006-1721: digestmd5
osv·2006-04-11·CVSS 2.6
CVE-2006-1721 [LOW] CVE-2006-1721: digestmd5
digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-1721 cyrus-sasl digest-md5 DoS
bugzilla·2007-08-15·CVSS 2.6
CVE-2006-1721 [LOW] CVE-2006-1721 cyrus-sasl digest-md5 DoS
CVE-2006-1721 cyrus-sasl digest-md5 DoS
+++ This bug was initially created as a clone of Bug #189814 +++
cyrus-sasl digest-md5 DoS
A DoS during SASL authentication digest-md5 negotiation could crash an
applications authenticating using the digest-md5 feature of
cyrus-sasl.
This issue was fixed upstream in 2.1.21.
An advisory regarding this issue was published here:
http://labs.musecurity.com/advisories/MU-200604-01.txt
The note from upstream verifying the isue was fixed in 2.1.21 is here:
http://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-sasl&msg=7775
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to
Bugzilla
CVE-2006-1721 cyrus-sasl digest-md5 DoS
bugzilla·2006-05-04·CVSS 2.6
CVE-2006-1721 [LOW] CVE-2006-1721 cyrus-sasl digest-md5 DoS
CVE-2006-1721 cyrus-sasl digest-md5 DoS
+++ This bug was initially created as a clone of Bug #189814 +++
cyrus-sasl digest-md5 DoS
A DoS during SASL authentication digest-md5 negotiation could crash an
applications authenticating using the digest-md5 feature of
cyrus-sasl.
This issue was fixed upstream in 2.1.21.
An advisory regarding this issue was published here:
http://labs.musecurity.com/advisories/MU-200604-01.txt
The note from upstream verifying the isue was fixed in 2.1.21 is here:
http://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-sasl&msg=7775
This issue also affects RHEL3
Discussion:
This issue affects RHL9, FC1, FC2 and FC3; and may also affect RHL 7.3,
though RHL 7.3 uses a much older version of cyrus-sasl. We will have to look
into it.
---
Fedora Core
Bugzilla
CVE-2006-1721 cyrus-sasl digest-md5 DoS
bugzilla·2006-04-24·CVSS 2.6
CVE-2006-1721 [LOW] CVE-2006-1721 cyrus-sasl digest-md5 DoS
CVE-2006-1721 cyrus-sasl digest-md5 DoS
cyrus-sasl digest-md5 DoS
A DoS during SASL authentication digest-md5 negotiation could crash an
applications authenticating using the digest-md5 feature of
cyrus-sasl.
This issue was fixed upstream in 2.1.21.
An advisory regarding this issue was published here:
http://labs.musecurity.com/advisories/MU-200604-01.txt
The note from upstream verifying the isue was fixed in 2.1.21 is here:
http://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-sasl&msg=7775
This issue also affects RHEL3
Discussion:
*** Bug 150091 has been marked as a duplicate of this bug. ***
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more informat
Bugzilla
CVE-2006-1721 cyrus-sasl digest-md5 DoS
bugzilla·2006-04-24·CVSS 2.6
CVE-2006-1721 [LOW] CVE-2006-1721 cyrus-sasl digest-md5 DoS
CVE-2006-1721 cyrus-sasl digest-md5 DoS
cyrus-sasl digest-md5 DoS
A DoS during SASL authentication digest-md5 negotiation could crash an
applications authenticating using the digest-md5 feature of
cyrus-sasl.
This issue was fixed upstream in 2.1.21.
An advisory regarding this issue was published here:
http://labs.musecurity.com/advisories/MU-200604-01.txt
The note from upstream verifying the isue was fixed in 2.1.21 is here:
http://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-sasl&msg=7775
Discussion:
cyrus-sasl-2.1.20-6 has been pushed for fc4, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.
---
This appears to have been fixed in an update earlier this year (see comment #1)
but neve
ftp://patches.sgi.com/support/free/security/advisories/20070901-01-P.aschttp://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-sasl&msg=7775http://labs.musecurity.com/advisories/MU-200604-01.txthttp://lists.apple.com/archives/security-announce/2006/Sep/msg00002.htmlhttp://lists.grok.org.uk/pipermail/full-disclosure/2006-April/044992.htmlhttp://secunia.com/advisories/19618http://secunia.com/advisories/19753http://secunia.com/advisories/19809http://secunia.com/advisories/19825http://secunia.com/advisories/19964http://secunia.com/advisories/20014http://secunia.com/advisories/22187http://secunia.com/advisories/26708http://secunia.com/advisories/26857http://secunia.com/advisories/27237http://secunia.com/advisories/30535http://securitytracker.com/id?1016960http://support.avaya.com/elmodocs2/security/ASA-2007-426.htmhttp://www.debian.org/security/2006/dsa-1042http://www.gentoo.org/security/en/glsa/glsa-200604-09.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:073http://www.novell.com/linux/security/advisories/2006_05_05.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0795.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0878.htmlhttp://www.securityfocus.com/archive/1/493080/100/0/threadedhttp://www.securityfocus.com/bid/17446http://www.trustix.org/errata/2006/0024http://www.vmware.com/security/advisories/VMSA-2008-0009.htmlhttp://www.vupen.com/english/advisories/2006/1306http://www.vupen.com/english/advisories/2006/3852http://www.vupen.com/english/advisories/2008/1744https://exchange.xforce.ibmcloud.com/vulnerabilities/25738https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9861https://usn.ubuntu.com/272-1/ftp://patches.sgi.com/support/free/security/advisories/20070901-01-P.aschttp://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-sasl&msg=7775http://labs.musecurity.com/advisories/MU-200604-01.txthttp://lists.apple.com/archives/security-announce/2006/Sep/msg00002.htmlhttp://lists.grok.org.uk/pipermail/full-disclosure/2006-April/044992.htmlhttp://secunia.com/advisories/19618http://secunia.com/advisories/19753http://secunia.com/advisories/19809http://secunia.com/advisories/19825http://secunia.com/advisories/19964http://secunia.com/advisories/20014http://secunia.com/advisories/22187http://secunia.com/advisories/26708http://secunia.com/advisories/26857http://secunia.com/advisories/27237http://secunia.com/advisories/30535http://securitytracker.com/id?1016960http://support.avaya.com/elmodocs2/security/ASA-2007-426.htmhttp://www.debian.org/security/2006/dsa-1042http://www.gentoo.org/security/en/glsa/glsa-200604-09.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:073http://www.novell.com/linux/security/advisories/2006_05_05.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0795.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0878.htmlhttp://www.securityfocus.com/archive/1/493080/100/0/threadedhttp://www.securityfocus.com/bid/17446http://www.trustix.org/errata/2006/0024http://www.vmware.com/security/advisories/VMSA-2008-0009.htmlhttp://www.vupen.com/english/advisories/2006/1306http://www.vupen.com/english/advisories/2006/3852http://www.vupen.com/english/advisories/2008/1744https://exchange.xforce.ibmcloud.com/vulnerabilities/25738https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9861https://usn.ubuntu.com/272-1/
2006-04-11
Published