CVE-2006-1721

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
11/04/2006
Last modified:
03/04/2025

Description

digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cyrus:sasl:2.1.18:*:*:*:*:*:*:*
cpe:2.3:a:cyrus:sasl:2.1.18_r1:*:*:*:*:*:*:*
cpe:2.3:a:cyrus:sasl:2.1.18_r2:*:*:*:*:*:*:*
cpe:2.3:a:cyrus:sasl:2.1.19:*:*:*:*:*:*:*
cpe:2.3:a:cyrus:sasl:2.1.20:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools