Logo
vulnerabilityCVE-2019-19906
Name
CVE-2019-19906
Source
NVD ( link)Debian ( link)
Description
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
cyrus-sasl
Patched

Vulnerability Ratings#


7.5
CVSSv31
5
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
openwrt
master
2.1.28-r5
Not Affected
openwrt
openwrt-25.12
2.1.28-r4
Not Affected
yocto
master
2.1.28
Patched
yocto
scarthgap
2.1.28
Patched

Resolved with patches#


cyrus-sasl (yocto:kirkstone)

#
Title
Author
Resolve
1
Fix #587
Changqing Li <changqing.li@windriver.com>
CVE-2019-19906

cyrus-sasl (yocto:master)

#
Title
Author
Resolve
1
Fix #587
Changqing Li <changqing.li@windriver.com>
CVE-2019-19906

cyrus-sasl (yocto:scarthgap)

#
Title
Author
Resolve
1
Fix #587
Changqing Li <changqing.li@windriver.com>
CVE-2019-19906