icon

We found results for “

CVE-2023-25567

Date: February 14, 2023

GSS-NTLMSSP, a mechglue plugin for the GSSAPI library that implements NTLM authentication, has an out-of-bounds read when decoding target information prior to version 1.2.0. The length of the "av_pair" is not checked properly for two of the elements which can trigger an out-of-bound read. The out-of-bounds read can be triggered via the main "gss_accept_sec_context" entry point and could cause a denial-of-service if the memory is unmapped. The issue is fixed in version 1.2.0.

Language: C

Severity Score

Severity Score

Weakness Type (CWE)

Out-of-bounds Read

CWE-125

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): HIGH

Do you need more information?

Contact Us