CVE-2019-19906

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
VendorProductVersion
cyrusimapcyrus-sasl
𝑥
< 2.1.28
debiandebian_linux
8.0
debiandebian_linux
9.0
debiandebian_linux
10.0
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
canonicalubuntu_linux
19.10
redhatjboss_enterprise_web_server
2.0.0
applemac_os_x
10.14.6
redhatenterprise_linux
5.0
redhatenterprise_linux
6.0
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux_eus
8.4
redhatenterprise_linux_for_ibm_z_systems
8.0
redhatenterprise_linux_for_ibm_z_systems_eus
8.4
redhatenterprise_linux_for_power_little_endian
8.0
redhatenterprise_linux_for_power_little_endian_eus
8.4
redhatenterprise_linux_server_aus
8.4
redhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions
8.4
redhatenterprise_linux_server_tus
8.4
redhatenterprise_linux_server_update_services_for_sap_solutions
8.4
appleipados
13.6
appleiphone_os
13.6
applemac_os_x
𝑥
< 10.13.6
applemac_os_x
10.13.0 ≤
𝑥
< 10.13.6
applemac_os_x
10.15.0 ≤
𝑥
< 10.15.6
applemac_os_x
10.13.6
applemac_os_x
10.13.6:security_update_2018-002
applemac_os_x
10.13.6:security_update_2018-003
applemac_os_x
10.13.6:security_update_2019-001
applemac_os_x
10.13.6:security_update_2019-002
applemac_os_x
10.13.6:security_update_2019-003
applemac_os_x
10.13.6:security_update_2019-004
applemac_os_x
10.13.6:security_update_2019-005
applemac_os_x
10.13.6:security_update_2019-006
applemac_os_x
10.13.6:security_update_2019-007
applemac_os_x
10.13.6:security_update_2020-001
applemac_os_x
10.13.6:security_update_2020-002
applemac_os_x
10.13.6:security_update_2020-003
applemac_os_x
10.14.6:security_update_2019-001
applemac_os_x
10.14.6:security_update_2019-002
applemac_os_x
10.14.6:security_update_2019-004
applemac_os_x
10.14.6:security_update_2019-005
applemac_os_x
10.14.6:security_update_2019-006
applemac_os_x
10.14.6:security_update_2019-007
applemac_os_x
10.14.6:security_update_2020-001
applemac_os_x
10.14.6:security_update_2020-002
applemac_os_x
10.14.6:security_update_2020-003
apachebookkeeper
4.12.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cyrus-sasl2
bullseye (security)
2.1.27+dfsg-2.1+deb11u1
fixed
bullseye
2.1.27+dfsg-2.1+deb11u1
fixed
bookworm
2.1.28+dfsg-10
fixed
sid
2.1.28+dfsg1-8
fixed
trixie
2.1.28+dfsg1-8
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cyrus-sasl2
eoan
Fixed 2.1.27+dfsg-1ubuntu0.1
released
disco
ignored
bionic
Fixed 2.1.27~101-g0780600+dfsg-3ubuntu2.1
released
xenial
Fixed 2.1.26.dfsg1-14ubuntu0.2
released
trusty
Fixed 2.1.25.dfsg1-17ubuntu0.1~esm1
released
References