Out-of-bounds read in GNU SASL - CVE-2022-2469

 

Out-of-bounds read in GNU SASL - CVE-2022-2469

Published: July 25, 2022


Vulnerability identifier: #VU65759
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2469
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition in the "lib/gssapi/server.c". A remote authenticated GSS-API client can send specially crafted request to the GNU SASL server, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.


Affected software

GNU SASL
SUSE Linux Enterprise Module for SUSE Manager Proxy
SUSE Linux Enterprise Module for SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Server
Fedora
Ubuntu
openEuler
gsasl (Ubuntu package)
gsasl (Debian package)
libgsasl
libgsasl-debugsource
libgsasl7
libgsasl7-debuginfo
libgsasl-lang
libgsasl-debuginfo
libgsasl-devel
HPE Moonshot 1500 Chassis Manager

How to mitigate CVE-2022-2469

Install updates from vendor's website.

GNU SASL - update to 2.0.1
gsasl (Ubuntu package) - update to Ubuntu Pro
gsasl (Debian package) - addressed in versions 1.8.0-8+deb10u1, 1.10.0-4+deb11u1
libgsasl - addressed in versions 1.8.0-9.el8, 1.10.0-15.el9, 1.10.0-15.el10_1, 1.10.0-15.el10_2, 1.10.0-15.fc42, 1.10.0-15.fc43, 1.10.0-15.fc44
libgsasl-debugsource - addressed in versions 1.8.0-150200.3.3.1, 1.8.0-150300.3.3.1, 1.8.0-150400.3.3.1
libgsasl7 - addressed in versions 1.8.0-150200.3.3.1, 1.8.0-150300.3.3.1, 1.8.0-150400.3.3.1
libgsasl7-debuginfo - addressed in versions 1.8.0-150200.3.3.1, 1.8.0-150300.3.3.1, 1.8.0-150400.3.3.1
libgsasl-lang - addressed in versions 1.8.0-150200.3.3.1, 1.8.0-150300.3.3.1, 1.8.0-150400.3.3.1
libgsasl-debuginfo - addressed in versions 1.8.1-1, 1.8.1-2
libgsasl-debugsource - addressed in versions 1.8.1-1, 1.8.1-2
libgsasl-devel - addressed in versions 1.8.1-1, 1.8.1-2
libgsasl - addressed in versions 1.8.1-1, 1.8.1-2
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43

External References

Related Security Bulletins