CVE-2019-17266
06.10.2019, 22:15
libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.Enginsight
| Vendor | Product | Version |
|---|---|---|
| gnome | libsoup | 2.65.1 ≤ 𝑥 < 2.66.4 |
| gnome | libsoup | 2.67.1 ≤ 𝑥 ≤ 2.68.1 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 19.04 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References