Server-Side Read-Out-of-Bounds Vulnerability in GNU SASL by GNU Project
CVE-2022-2469
3.8LOW
What is CVE-2022-2469?
A server-side read-out-of-bounds vulnerability exists in GNU SASL, which can be exploited by a maliciously authenticated GSS-API client. This flaw may allow attackers to read data beyond the intended buffer allocations, potentially leading to unauthorized access to sensitive data. The issue affects certain versions of the GNU SASL, making it imperative for users to apply appropriate patches or updates to mitigate risks.
Affected Version(s)
GNU SASL >=0.0.0, <2.0.1