CVE-2019-17266

libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnome:libsoup:*:*:*:*:*:*:*:*
cpe:2.3:a:gnome:libsoup:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*

History

21 Nov 2024, 04:31

Type Values Removed Values Added
References () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=941912 - Third Party Advisory () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=941912 - Third Party Advisory
References () https://github.com/Kirin-say/Vulnerabilities/blob/master/CVE-2019-17266_POC.md - Third Party Advisory () https://github.com/Kirin-say/Vulnerabilities/blob/master/CVE-2019-17266_POC.md - Third Party Advisory
References () https://gitlab.gnome.org/GNOME/libsoup/commit/88b7dff4467f4151afae244ea7d1223753cd05ab - Third Party Advisory () https://gitlab.gnome.org/GNOME/libsoup/commit/88b7dff4467f4151afae244ea7d1223753cd05ab - Third Party Advisory
References () https://gitlab.gnome.org/GNOME/libsoup/commit/f8a54ac85eec2008c85393f331cdd251af8266ad - Third Party Advisory () https://gitlab.gnome.org/GNOME/libsoup/commit/f8a54ac85eec2008c85393f331cdd251af8266ad - Third Party Advisory
References () https://gitlab.gnome.org/GNOME/libsoup/issues/173 - Broken Link, Issue Tracking, Third Party Advisory () https://gitlab.gnome.org/GNOME/libsoup/issues/173 - Broken Link, Issue Tracking, Third Party Advisory
References () https://security-tracker.debian.org/tracker/CVE-2019-17266 - Third Party Advisory () https://security-tracker.debian.org/tracker/CVE-2019-17266 - Third Party Advisory
References () https://usn.ubuntu.com/4152-1/ - Third Party Advisory () https://usn.ubuntu.com/4152-1/ - Third Party Advisory
References () https://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg1705054.html - () https://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg1705054.html -

07 Nov 2023, 03:06

Type Values Removed Values Added
References
  • {'url': 'https://www.mail-archive.com/debian-bugs-dist@lists.debian.org/msg1705054.html', 'name': 'https://www.mail-archive.com/debian-bugs-dist@lists.debian.org/msg1705054.html', 'tags': ['Third Party Advisory'], 'refsource': 'MISC'}
  • () https://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg1705054.html -

Information

Published : 2019-10-06 22:15

Updated : 2024-11-21 04:31


NVD link : CVE-2019-17266

Mitre link : CVE-2019-17266

CVE.ORG link : CVE-2019-17266


JSON object : View

Products Affected

canonical

  • ubuntu_linux

gnome

  • libsoup
CWE
CWE-125

Out-of-bounds Read