CVE-2019-17266
06.10.2019, 22:15
libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.Enginsight
Vendor | Product | Version |
---|---|---|
gnome | libsoup | 2.65.1 ≤ 𝑥 < 2.66.4 |
gnome | libsoup | 2.67.1 ≤ 𝑥 ≤ 2.68.1 |
canonical | ubuntu_linux | 18.04 |
canonical | ubuntu_linux | 19.04 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References