Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-25566
HistoryFeb 14, 2023 - 12:00 a.m.

CVE-2023-25566

2023-02-1400:00:00
ubuntu.com
ubuntu.com
8
gssapi
ntlm authentication
memory leak

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

45.0%

GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements
NTLM authentication. Prior to version 1.2.0, a memory leak can be triggered
when parsing usernames which can trigger a denial-of-service. The domain
portion of a username may be overridden causing an allocated memory area
the size of the domain name to be leaked. An attacker can leak memory via
the main gss_accept_sec_context entry point, potentially causing a
denial-of-service. This issue is fixed in version 1.2.0.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

45.0%