Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-25565
HistoryFeb 14, 2023 - 12:00 a.m.

CVE-2023-25565

2023-02-1400:00:00
ubuntu.com
ubuntu.com
8
gssapi library
ntlm authentication
denial of service
mechglue plugin

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

45.8%

GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements
NTLM authentication. Prior to version 1.2.0, an incorrect free when
decoding target information can trigger a denial of service. The error
condition incorrectly assumes the cb and sh buffers contain a copy of
the data that needs to be freed. However, that is not the case. This
vulnerability can be triggered via the main gss_accept_sec_context entry
point. This will likely trigger an assertion failure in free, causing a
denial-of-service. This issue is fixed in version 1.2.0.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

45.8%