CVE-2019-19906: High severity Apple macOS Catalina vulnerability
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in sasladdstring in common.c in cyrus-sasl.
Other sources
Mail. An out-of-bounds write issue was addressed with improved bounds checking.
Credit
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9927
- CVE-2020-9884
- CVE-2020-9889
- CVE-2020-9888
- CVE-2020-9890
- CVE-2020-9891
- CVE-2020-9928
- CVE-2020-9929
- CVE-2020-9870
- CVE-2020-9866
- CVE-2020-9869
- CVE-2020-9949
- CVE-2020-9934
- CVE-2020-9883
- CVE-2020-9865
- CVE-2020-9900
- CVE-2020-9980
- CVE-2020-9799
- CVE-2020-9913
- CVE-2020-27933
- CVE-2020-11758
- CVE-2020-11759
- CVE-2020-11760
- CVE-2020-11761
- CVE-2020-11762
- CVE-2020-11763
- CVE-2020-11764
- CVE-2020-11765
- CVE-2020-9871
- CVE-2020-9872
- CVE-2020-9874
- CVE-2020-9879
- CVE-2020-9936
- CVE-2020-9937
- CVE-2020-9919
- CVE-2020-9876
- CVE-2020-9873
- CVE-2020-9938
- CVE-2020-9877
- CVE-2020-9875
- CVE-2020-9984
- CVE-2020-9887
- CVE-2020-9908
- CVE-2020-9990
- CVE-2020-9921
- CVE-2019-14899
- CVE-2020-9904
- CVE-2020-9924
- CVE-2020-9892
- CVE-2020-9863
- CVE-2020-9902
- CVE-2020-9905
- CVE-2020-9997
- CVE-2020-9926
- CVE-2020-9994
- CVE-2020-9935
- CVE-2019-19906
- CVE-2020-9920
- CVE-2020-9922
- CVE-2020-9885
- CVE-2020-9878
- CVE-2020-9880
- CVE-2020-9881
- CVE-2020-9882
- CVE-2020-9940
- CVE-2020-9985
- CVE-2020-12243
- CVE-2020-10878
- CVE-2020-12723
- CVE-2014-9512
- CVE-2020-9930
- CVE-2020-9939
- CVE-2020-9864
- CVE-2020-9868
- CVE-2020-9854
- CVE-2020-9901
- CVE-2019-20807
- CVE-2020-9898
- CVE-2020-9918
- CVE-2020-9899
- CVE-2020-9906
- CVE-2020-9907
- CVE-2020-9931
- CVE-2020-9933
- CVE-2020-9914
- CVE-2020-9923
- CVE-2020-9909
- CVE-2020-9903
- CVE-2020-9911
- CVE-2020-9894
- CVE-2020-9915
- CVE-2020-9893
- CVE-2020-9895
- CVE-2020-9925
- CVE-2020-9910
- CVE-2020-9916
- CVE-2020-9862
- CVE-2020-6514
- CVE-2020-9917
Frequently Asked Questions
What is CVE-2019-19906?
CVE-2019-19906 is a vulnerability in Mail that allows for an out-of-bounds write issue.
How does CVE-2019-19906 affect Apple macOS Catalina?
CVE-2019-19906 affects Apple macOS Catalina version up to and excluding 10.15.6.
How does CVE-2019-19906 affect Apple Mojave?
CVE-2019-19906 affects Apple Mojave.
How does CVE-2019-19906 affect Apple High Sierra?
CVE-2019-19906 affects Apple High Sierra.
How does CVE-2019-19906 affect Apple iOS?
CVE-2019-19906 affects Apple iOS version up to and excluding 13.6.
How does CVE-2019-19906 affect Apple iPadOS?
CVE-2019-19906 affects Apple iPadOS version up to and excluding 13.6.
How can I fix CVE-2019-19906?
To fix CVE-2019-19906, update your system to the latest version of the affected software.
Where can I find more information about CVE-2019-19906?
You can find more information about CVE-2019-19906 in the references provided by Apple: [Reference 1](https://support.apple.com/en-us/HT211289) and [Reference 2](https://support.apple.com/en-us/HT211288).