Search CVE reports


Toggle filters

1 – 5 of 5 results


CVE-2023-25567

Medium priority

Some fixes available 4 of 7

GSS-NTLMSSP, a mechglue plugin for the GSSAPI library that implements NTLM authentication, has an out-of-bounds read when decoding target information prior to version 1.2.0. The length of the `av_pair` is not checked properly for...

1 affected package

gss-ntlmssp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gss-ntlmssp Not affected Fixed Fixed Fixed
Show less packages

CVE-2023-25566

Medium priority
Ignored

GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, a memory leak can be triggered when parsing usernames which can trigger a denial-of-service. The domain portion...

1 affected package

gss-ntlmssp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gss-ntlmssp Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-25565

Medium priority

Some fixes available 4 of 7

GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, an incorrect free when decoding target information can trigger a denial of service. The error condition...

1 affected package

gss-ntlmssp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gss-ntlmssp Not affected Fixed Fixed Fixed
Show less packages

CVE-2023-25564

Medium priority

Some fixes available 4 of 7

GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, memory corruption can be triggered when decoding UTF16 strings. The variable `outlen` was not initialized and...

1 affected package

gss-ntlmssp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gss-ntlmssp Not affected Fixed Fixed Fixed
Show less packages

CVE-2023-25563

Medium priority

Some fixes available 4 of 7

GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, multiple out-of-bounds reads when decoding NTLM fields can trigger a denial of service. A 32-bit integer overflow...

1 affected package

gss-ntlmssp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gss-ntlmssp Not affected Fixed Fixed Fixed
Show less packages