Lucene search

K

Gss-Ntlmssp Security Vulnerabilities

cve
cve

CVE-2023-25563

GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, multiple out-of-bounds reads when decoding NTLM fields can trigger a denial of service. A 32-bit integer overflow condition can lead to incorrect checks of consistency of length of i...

7.5CVSS

7.4AI Score

0.001EPSS

2023-02-14 06:15 PM
37
cve
cve

CVE-2023-25564

GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, memory corruption can be triggered when decoding UTF16 strings. The variable outlen was not initialized and could cause writing a zero to an arbitrary place in memory if ntlm_str_con...

8.2CVSS

8AI Score

0.001EPSS

2023-02-14 06:15 PM
43
cve
cve

CVE-2023-25565

GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, an incorrect free when decoding target information can trigger a denial of service. The error condition incorrectly assumes the cb and sh buffers contain a copy of the data that need...

7.5CVSS

7.1AI Score

0.001EPSS

2023-02-14 06:15 PM
37
cve
cve

CVE-2023-25566

GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, a memory leak can be triggered when parsing usernames which can trigger a denial-of-service. The domain portion of a username may be overridden causing an allocated memory area the s...

7.5CVSS

7.1AI Score

0.001EPSS

2023-02-14 06:15 PM
34
cve
cve

CVE-2023-25567

GSS-NTLMSSP, a mechglue plugin for the GSSAPI library that implements NTLM authentication, has an out-of-bounds read when decoding target information prior to version 1.2.0. The length of the av_pair is not checked properly for two of the elements which can trigger an out-of-bound read. The out-of-...

7.5CVSS

7AI Score

0.001EPSS

2023-02-14 06:15 PM
36