CVE-2006-1721
cyrus-sasl2 - programming error
EPSS 2.4%
描述
digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.
如何修補 CVE-2006-1721
要修補 CVE-2006-1721,請將受影響套件升級到下列已修補版本。
- Debian/cyrus-sasl2—升級至 2.1.19.dfsg1-0.2 或更新版本
- Debian/cyrus-sasl2—升級至 2.1.19-1.5sarge1 或更新版本
CVE-2006-1721 正在被利用嗎?
低 — EPSS 為 2.4%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 2.1.19.dfsg1-0.2
- from 0, < 2.1.19-1.5sarge1