CVE-2023-25563
- EPSS 0.08%
- Veröffentlicht 14.02.2023 18:15:13
- Zuletzt bearbeitet 21.11.2024 07:49:44
GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, multiple out-of-bounds reads when decoding NTLM fields can trigger a denial of service. A 32-bit integer overflow condition can lead ...
CVE-2023-25564
- EPSS 0.11%
- Veröffentlicht 14.02.2023 18:15:13
- Zuletzt bearbeitet 21.11.2024 07:49:44
GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, memory corruption can be triggered when decoding UTF16 strings. The variable `outlen` was not initialized and could cause writing a z...
CVE-2023-25565
- EPSS 0.09%
- Veröffentlicht 14.02.2023 18:15:13
- Zuletzt bearbeitet 21.11.2024 07:49:44
GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, an incorrect free when decoding target information can trigger a denial of service. The error condition incorrectly assumes the `cb` ...
CVE-2023-25566
- EPSS 0.13%
- Veröffentlicht 14.02.2023 18:15:13
- Zuletzt bearbeitet 21.11.2024 07:49:44
GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, a memory leak can be triggered when parsing usernames which can trigger a denial-of-service. The domain portion of a username may be ...
CVE-2023-25567
- EPSS 0.09%
- Veröffentlicht 14.02.2023 18:15:13
- Zuletzt bearbeitet 21.11.2024 07:49:44
GSS-NTLMSSP, a mechglue plugin for the GSSAPI library that implements NTLM authentication, has an out-of-bounds read when decoding target information prior to version 1.2.0. The length of the `av_pair` is not checked properly for two of the elements ...