CVE-2022-2469

gitlab-org/cves
on gitlab
gsasl/gsasl
on gitlab

Published

Severity

CVSS v3:
8.1 HIGH
CVSS v2:
N/A

Description

GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:gnul:gnu_sasl:*:*:*:*:*:*:*:*n/a2.0.1*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*n/an/a10.0
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*n/an/a11.0
cpe:2.3:a:gnu:gnu_sasl:*:*:*:*:*:*:*:*n/a2.0.1*

External Links