VYPR

rpm package

opensuse/gsasl&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/gsasl&distro=openSUSE%20Leap%2016.0

Vulnerabilities (2)

  • CVE-2026-56968LowJun 23, 2026
    affected < 2.2.1-160000.4.1fixed 2.2.1-160000.4.1

    GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.

  • CVE-2026-48829HigMay 24, 2026
    affected < 2.2.1-160000.3.1fixed 2.2.1-160000.3.1

    In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.