HIGH · 7.5

CVE-2019-19906

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an...

Vulnerability Description

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
CyrusimapCyrus-Sasl< 2.1.28
DebianDebian Linux8.0
CanonicalUbuntu Linux12.04
FedoraprojectFedora31
RedhatJboss Enterprise Web Server2.0.0
AppleMac Os X10.14.6
RedhatEnterprise Linux5.0
RedhatEnterprise Linux Eus8.4
RedhatEnterprise Linux For Ibm Z Systems8.0
RedhatEnterprise Linux For Ibm Z Systems Eus8.4
RedhatEnterprise Linux For Power Little Endian8.0
RedhatEnterprise Linux For Power Little Endian Eus8.4
RedhatEnterprise Linux Server Aus8.4
RedhatEnterprise Linux Server For Power Little Endian Update Services For Sap Solutions8.4
RedhatEnterprise Linux Server Tus8.4
RedhatEnterprise Linux Server Update Services For Sap Solutions8.4
AppleIpados13.6
AppleIphone Os13.6
ApacheBookkeeper4.12.1
CentosCentos7.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-19906?

CVE-2019-19906 is a vulnerability with a CVSS score of 7.5 (HIGH). cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an...

How severe is CVE-2019-19906?

CVE-2019-19906 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-19906?

Check the references section above for vendor advisories and patch information. Affected products include: Cyrusimap Cyrus-Sasl, Debian Debian Linux, Canonical Ubuntu Linux, Fedoraproject Fedora, Redhat Jboss Enterprise Web Server.