OSV-2025-32

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/poco/OSV-2025-32.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2025-32
Published
2025-01-16T00:01:09.535772Z
Modified
2025-01-16T00:01:09.536403Z
Summary
UNKNOWN READ in std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<ch
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=389754841

Crash type: UNKNOWN READ
Crash state:
std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<ch
Poco::Net::NTLMCredentials::parseChallengeMessage
Poco::Net::HTTPNTLMCredentials::createNTLMMessage
References

Affected packages

OSS-Fuzz / poco

Package

Name
poco
Purl
pkg:generic/poco

Affected ranges

Type
GIT
Repo
https://github.com/pocoproject/poco
Events

Affected versions

poco-1.*
poco-1.14.0-release
poco-1.14.1-release

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

source
"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/poco/OSV-2025-32.yaml"
introduced_range
"03c35cff930e421199b586c33a00eb6cc537ba28:3a8c6a72b13d1a6ce4e45e4f0f1a428b308b531e"
fixed_range
"bb0b8f8e81e309ec4e52389d225f0a89c260411b:be2748de0f34f7c48d5055c268bd12ecd32f8dc0"