OSV-2024-1216

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/poco/OSV-2024-1216.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2024-1216
Published
2024-10-13T00:11:43Z
Modified
2025-03-18T00:32:42Z
Summary
Use-of-uninitialized-value in Poco::Net::NTLMCredentials::parseChallengeMessage
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=372764172

Crash type: Use-of-uninitialized-value
Crash state:
Poco::Net::NTLMCredentials::parseChallengeMessage
Poco::Net::HTTPNTLMCredentials::createNTLMMessage
Poco::Net::HTTPNTLMCredentials::authenticate
References

Affected packages

OSS-Fuzz / poco

Package

Name
poco
Purl
pkg:generic/poco

Affected ranges

Affected versions

poco-1.*
poco-1.14.0-release

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

fixed_range
"5652837b8f622f2e8d6aad5d286c78587a4a37b4:7297033be78f8fab21cce57fceb445e76bdbee26"
introduced_range
"03c35cff930e421199b586c33a00eb6cc537ba28:3a8c6a72b13d1a6ce4e45e4f0f1a428b308b531e"
source
"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/poco/OSV-2024-1216.yaml"