rpm package
opensuse/gsasl&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/gsasl&distro=openSUSE%20Leap%2016.0
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-56968 | Low | 3.7 | < 2.2.1-160000.4.1 | 2.2.1-160000.4.1 | Jun 23, 2026 | GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server. | |
| CVE-2026-48829 | Hig | 7.5 | < 2.2.1-160000.3.1 | 2.2.1-160000.3.1 | May 24, 2026 | In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c. |
- affected < 2.2.1-160000.4.1fixed 2.2.1-160000.4.1
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
- affected < 2.2.1-160000.3.1fixed 2.2.1-160000.3.1
In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.