CVE-2006-1721
Last modified
CVE-2006-1721 is a vulnerability of currently unknown severity. digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.. EPSS estimates a 2.43% chance of exploitation in the next 30 days.
Description
digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cyrus | Sasl | 2.1.18 |
| Cyrus | Sasl | 2.1.18_r1 |
| Cyrus | Sasl | 2.1.18_r2 |
| Cyrus | Sasl | 2.1.19 |
| Cyrus | Sasl | 2.1.20 |
References
- http://secunia.com/advisories/19618Patch, Vendor Advisory
- http://secunia.com/advisories/19753Vendor Advisory
- http://secunia.com/advisories/19809Vendor Advisory
- http://secunia.com/advisories/19825Vendor Advisory
- http://secunia.com/advisories/19964Vendor Advisory
- http://secunia.com/advisories/20014Vendor Advisory
- http://secunia.com/advisories/22187Vendor Advisory
- http://secunia.com/advisories/26708Vendor Advisory
- http://secunia.com/advisories/26857Vendor Advisory
- http://secunia.com/advisories/27237Vendor Advisory
- http://secunia.com/advisories/30535Vendor Advisory
- http://www.vupen.com/english/advisories/2006/1306Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3852Vendor Advisory
- http://www.vupen.com/english/advisories/2008/1744Vendor Advisory
- http://secunia.com/advisories/19618Patch, Vendor Advisory
- http://secunia.com/advisories/19753Vendor Advisory
- http://secunia.com/advisories/19809Vendor Advisory
- http://secunia.com/advisories/19825Vendor Advisory
- http://secunia.com/advisories/19964Vendor Advisory
- http://secunia.com/advisories/20014Vendor Advisory
- http://secunia.com/advisories/22187Vendor Advisory
- http://secunia.com/advisories/26708Vendor Advisory
- http://secunia.com/advisories/26857Vendor Advisory
- http://secunia.com/advisories/27237Vendor Advisory
- http://secunia.com/advisories/30535Vendor Advisory
- http://www.vupen.com/english/advisories/2006/1306Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3852Vendor Advisory
- http://www.vupen.com/english/advisories/2008/1744Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-1721?
How severe is CVE-2006-1721?
How do I fix CVE-2006-1721?
Are you affected by CVE-2006-1721?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
