Lucene search

K
redhatcveRedhat.comRH:CVE-2023-25567
HistoryFeb 21, 2023 - 8:59 a.m.

CVE-2023-25567

2023-02-2108:59:24
redhat.com
access.redhat.com
9
gss-ntlmssp
gssapi library
out-of-bounds read

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

45.8%

A flaw was found in GSS-NTLMSSP, a mechglue plugin for the GSSAPI library that implements NTLM authentication. It has an out-of-bounds read when decoding target information. The length of the av_pair is not checked properly for two of the elements, which can trigger an out-of-bounds read via the main gss_accept_sec_context entry point and could cause a denial of service if the memory is unmapped.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

45.8%