First published: Thu Dec 19 2019(Updated: )
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.
Credit: CVE-2019-19906 CVE-2019-19906 cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/cyrus-sasl2 | <=2.1.27~101-g0780600+dfsg-3<=2.1.27+dfsg-1 | 2.1.27+dfsg-1+deb10u1 2.1.27~101-g0780600+dfsg-3+deb9u1 2.1.27+dfsg-2 |
Apple macOS Catalina | <10.15.6 | 10.15.6 |
Apple Mojave | ||
Apple High Sierra | ||
Apple iOS | <13.6 | 13.6 |
Apple iPadOS | <13.6 | 13.6 |
Cyrusimap Cyrus-sasl | <2.1.28 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.10 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
Redhat Jboss Enterprise Web Server | =2.0.0 | |
Apple Mac OS X | =10.14.6 | |
Redhat Enterprise Linux | =5.0 | |
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux Eus | =8.4 | |
Redhat Enterprise Linux For Ibm Z Systems | =8.0 | |
Redhat Enterprise Linux For Ibm Z Systems Eus | =8.4 | |
Redhat Enterprise Linux For Power Little Endian | =8.0 | |
Redhat Enterprise Linux For Power Little Endian Eus | =8.4 | |
Redhat Enterprise Linux Server Aus | =8.4 | |
Redhat Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions | =8.4 | |
Redhat Enterprise Linux Server Tus | =8.4 | |
Redhat Enterprise Linux Server Update Services For Sap Solutions | =8.4 | |
Apple iPadOS | =13.6 | |
Apple iPhone OS | =13.6 | |
Apple Mac OS X | <10.13.6 | |
Apple Mac OS X | >=10.13.0<10.13.6 | |
Apple Mac OS X | >=10.15.0<10.15.6 | |
Apple Mac OS X | =10.13.6 | |
Apple Mac OS X | =10.13.6-security_update_2018-002 | |
Apple Mac OS X | =10.13.6-security_update_2018-003 | |
Apple Mac OS X | =10.13.6-security_update_2019-001 | |
Apple Mac OS X | =10.13.6-security_update_2019-002 | |
Apple Mac OS X | =10.13.6-security_update_2019-003 | |
Apple Mac OS X | =10.13.6-security_update_2019-004 | |
Apple Mac OS X | =10.13.6-security_update_2019-005 | |
Apple Mac OS X | =10.13.6-security_update_2019-006 | |
Apple Mac OS X | =10.13.6-security_update_2019-007 | |
Apple Mac OS X | =10.13.6-security_update_2020-001 | |
Apple Mac OS X | =10.13.6-security_update_2020-002 | |
Apple Mac OS X | =10.13.6-security_update_2020-003 | |
Apple Mac OS X | =10.14.6-security_update_2019-001 | |
Apple Mac OS X | =10.14.6-security_update_2019-002 | |
Apple Mac OS X | =10.14.6-security_update_2019-004 | |
Apple Mac OS X | =10.14.6-security_update_2019-005 | |
Apple Mac OS X | =10.14.6-security_update_2019-006 | |
Apple Mac OS X | =10.14.6-security_update_2019-007 | |
Apple Mac OS X | =10.14.6-security_update_2020-001 | |
Apple Mac OS X | =10.14.6-security_update_2020-002 | |
Apple Mac OS X | =10.14.6-security_update_2020-003 | |
Apache Bookkeeper | =4.12.1 | |
CentOS CentOS | =7.0 | |
ubuntu/cyrus-sasl2 | <2.1.27~101- | 2.1.27~101- |
ubuntu/cyrus-sasl2 | <2.1.27+dfsg-1ubuntu0.1 | 2.1.27+dfsg-1ubuntu0.1 |
ubuntu/cyrus-sasl2 | <2.1.25.dfsg1-17ubuntu0.1~ | 2.1.25.dfsg1-17ubuntu0.1~ |
ubuntu/cyrus-sasl2 | <2.1.26.dfsg1-14ubuntu0.2 | 2.1.26.dfsg1-14ubuntu0.2 |
All of | ||
Apache Bookkeeper | =4.12.1 | |
CentOS CentOS | =7.0 | |
debian/cyrus-sasl2 | 2.1.27+dfsg-2.1+deb11u1 2.1.28+dfsg-10 2.1.28+dfsg1-7 2.1.28+dfsg1-8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-19906 is a vulnerability in Mail that allows for an out-of-bounds write issue.
CVE-2019-19906 affects Apple macOS Catalina version up to and excluding 10.15.6.
CVE-2019-19906 affects Apple Mojave.
CVE-2019-19906 affects Apple High Sierra.
CVE-2019-19906 affects Apple iOS version up to and excluding 13.6.
CVE-2019-19906 affects Apple iPadOS version up to and excluding 13.6.
To fix CVE-2019-19906, update your system to the latest version of the affected software.
You can find more information about CVE-2019-19906 in the references provided by Apple: [Reference 1](https://support.apple.com/en-us/HT211289) and [Reference 2](https://support.apple.com/en-us/HT211288).