OSV-2025-291

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/poco/OSV-2025-291.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2025-291
Published
2025-04-20T00:07:34.286645Z
Modified
2025-04-20T00:07:34.287298Z
Summary
Use-of-uninitialized-value in Poco::Net::NTLMCredentials::parseChallengeMessage
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=411466303

Crash type: Use-of-uninitialized-value
Crash state:
Poco::Net::NTLMCredentials::parseChallengeMessage
Poco::Net::HTTPNTLMCredentials::createNTLMMessage
Poco::Net::HTTPNTLMCredentials::authenticate
References

Affected packages

OSS-Fuzz / poco

Package

Name
poco
Purl
pkg:generic/poco

Affected ranges

Type
GIT
Repo
https://github.com/pocoproject/poco
Events

Affected versions

poco-1.*

poco-1.14.0-release
poco-1.14.1-release

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

{
    "introduced_range": "03c35cff930e421199b586c33a00eb6cc537ba28:3a8c6a72b13d1a6ce4e45e4f0f1a428b308b531e",
    "fixed_range": "11619a9e95c2ce14a0edfeddb8c1a0a1c926ba7f:ca571245e6cc38177f4c1f27fc22d807b8468a47"
}