In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "gsasl",
"binary_version": "2.2.1-1willsync1ubuntu0.1"
},
{
"binary_name": "gsasl-common",
"binary_version": "2.2.1-1willsync1ubuntu0.1"
},
{
"binary_name": "libgsasl18",
"binary_version": "2.2.1-1willsync1ubuntu0.1"
}
]
}