>> Cyrus SASL DIGEST-MD5 Pre-Authentication Denial of Service Vulnerability
Title : Cyrus SASL DIGEST-MD5 Pre-Authentication Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2006-1306 CVE ID : CVE-2006-1721
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-04-11
Technical Description
A vulnerability has been identified in Cyrus SASL library, which could be exploited by remote attackers to cause a denial of service. This flaw is due to an error in the SASL DIGEST-MD5 authentication module that does not properly handle malformed requests, which could be exploited by remote unauthenticated attackers to crash applications linked against the vulnerable library.