cbcvebase.
CVE-2019-19906
published 2019-12-19

CVE-2019-19906: cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
apachebookkeeper
appleios_13.6_and_ipados
appleipados
appleiphone_os
applemac_os_x< 10.13.610.13.6
applemac_os_x
applemac_os_x
applemac_os_x>= 10.13.0 < 10.13.610.13.6
applemac_os_x>= 10.15.0 < 10.15.610.15.6
applemacos_catalina_10.15.6_security_update_2020-004_mojave_security_update_2020-004
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
cyrusimapcyrus-sasl< 2.1.282.1.28
debiancyrus-sasl2< cyrus-sasl2 2.1.27+dfsg-2 (bookworm)cyrus-sasl2 2.1.27+dfsg-2 (bookworm)
debiandebian_linux
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_cyrus-sasl_2.1.27-10_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH