Description
digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.
CVSS vector
AV:N/AC:H/C:N/I:N/A:PExploitability: 4.9 | Impact: 2.9Complexity: High
Confidentiality: None
Integrity: None
Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-x5mm-w7g6-r6fq: digestmd5↗2022-05-03 ▶ CVEListCVE-2006-1721: digestmd5↗2006-04-11 ▶ OSVCVE-2006-1721: digestmd5↗2006-04-11 ▶ 📋Vendor Advisories
3Ubuntucyrus-sasl2 vulnerability↗2006-04-24 ▶ DebianCVE-2006-1721: cyrus-sasl2 - digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) lib...↗2006 ▶ Red Hatcyrus-sasl digest-md5 DoS↗2005-05-15 ▶ 💬Community
4BugzillaCVE-2006-1721 cyrus-sasl digest-md5 DoS↗2007-08-15 ▶ BugzillaCVE-2006-1721 cyrus-sasl digest-md5 DoS↗2006-05-04 ▶ BugzillaCVE-2006-1721 cyrus-sasl digest-md5 DoS↗2006-04-24 ▶ BugzillaCVE-2006-1721 cyrus-sasl digest-md5 DoS↗2006-04-24 ▶