CVE-2019-17266

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
06/10/2019
Last modified:
07/11/2023

Description

libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnome:libsoup:*:*:*:*:*:*:*:* 2.65.1 (including) 2.66.4 (excluding)
cpe:2.3:a:gnome:libsoup:*:*:*:*:*:*:*:* 2.67.1 (including) 2.68.1 (including)
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*