CVE-2022-2469
published 2022-07-19CVE-2022-2469: GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client
PriorityP343high8.1CVSS 3.1
AVNACLPRLUINSUCHINAH
EPSS
1.09%
61.5th percentile
GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | gsasl | < gsasl 2.0.1-1 (bookworm) | gsasl 2.0.1-1 (bookworm) |
| gnu | gnu_sasl | < 2.0.1 | 2.0.1 |
| gnu | gnu_sasl | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv8.1HIGH
vendor_debian3.8LOW
vendor_redhat3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU SASL vulnerability
vendor_ubuntu·2023-06-15
CVE-2022-2469 GNU SASL vulnerability
Title: GNU SASL vulnerability
Summary: gsasl could possibly be made crash or expose sensitive information
over the network.
It was discovered that GNU SASL's GSSAPI server could make an
out-of-bounds reads if given specially crafted GSS-API authentication
data. A remote attacker could possibly use this issue to cause a
denial of service or to expose sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libgsasl: Out of bounds read causes DoS
vendor_redhat·2022-07-18·CVSS 3.8
CVE-2022-2469 [LOW] CWE-125 libgsasl: Out of bounds read causes DoS
libgsasl: Out of bounds read causes DoS
GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client
Statement: This flaw affects Community Projects only; no supported Red Hat products are affected.
Debian
CVE-2022-2469: gsasl - GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GS...
vendor_debian·2022·CVSS 3.8
CVE-2022-2469 [LOW] CVE-2022-2469: gsasl - GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GS...
GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client
Scope: local
bookworm: resolved (fixed in 2.0.1-1)
bullseye: resolved (fixed in 1.10.0-4+deb11u1)
forky: resolved (fixed in 2.0.1-1)
sid: resolved (fixed in 2.0.1-1)
trixie: resolved (fixed in 2.0.1-1)
GHSA
GHSA-r9xr-xfwx-6crw: GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client
ghsa_unreviewed·2022-07-20
CVE-2022-2469 [HIGH] CWE-125 GHSA-r9xr-xfwx-6crw: GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client
GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client
OSV
CVE-2022-2469: GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client
osv·2022-07-19·CVSS 8.1
CVE-2022-2469 [HIGH] CVE-2022-2469: GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client
GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client
No detection rules found.
No public exploits indexed.
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2469.jsonhttps://gitlab.com/gsasl/gsasl/-/commit/796e4197f696261c1f872d7576371232330bcc30https://www.debian.org/security/2022/dsa-5189https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2469.jsonhttps://gitlab.com/gsasl/gsasl/-/commit/796e4197f696261c1f872d7576371232330bcc30https://www.debian.org/security/2022/dsa-5189
2022-07-19
Published