Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4618-1 | gsasl security update |
Fri, 05 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 26 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 24 May 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | NULL Pointer Dereference in DIGEST-MD5 Handling of GNU SASL 2.2.3 and Earlier |
Sun, 24 May 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c. | |
| First Time appeared |
Gnu
Gnu gnu Sasl |
|
| Weaknesses | CWE-476 | |
| CPEs | cpe:2.3:a:gnu:gnu_sasl:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gnu
Gnu gnu Sasl |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-05T16:00:19.437Z
Reserved: 2026-05-24T02:22:03.024Z
Link: CVE-2026-48829
Updated: 2026-06-05T16:00:19.437Z
Status : Deferred
Published: 2026-05-24T04:16:39.150
Modified: 2026-06-17T10:55:15.893
Link: CVE-2026-48829
No data.
OpenCVE Enrichment
Updated: 2026-05-25T11:30:23Z
Debian DLA