Lucene search

K
cve[email protected]CVE-2006-1721
HistoryApr 11, 2006 - 11:02 p.m.

CVE-2006-1721

2006-04-1123:02:00
CWE-20
web.nvd.nist.gov
44
cve-2006-1721
cmu cyrus
sasl library
denial of service
remote attack

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

9.2 High

AI Score

Confidence

High

0.073 Low

EPSS

Percentile

94.1%

digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.

Affected configurations

NVD
Node
cyrussaslMatch2.1.18
OR
cyrussaslMatch2.1.18_r1
OR
cyrussaslMatch2.1.18_r2
OR
cyrussaslMatch2.1.19
OR
cyrussaslMatch2.1.20

References

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

9.2 High

AI Score

Confidence

High

0.073 Low

EPSS

Percentile

94.1%