1 results (0.002 seconds)

CVSS: 2.6EPSS: 7%CPEs: 5EXPL: 0

digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation. • ftp://patches.sgi.com/support/free/security/advisories/20070901-01-P.asc http://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-sasl&msg=7775 http://labs.musecurity.com/advisories/MU-200604-01.txt http://lists.apple.com/archives/security-announce/2006/Sep/msg00002.html http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/044992.html http://secunia.com/advisories/19618 http://secunia.com/advisories/19753 http://secunia.com/advisories/19809 http://secunia.com/ • CWE-20: Improper Input Validation •