UBUNTU-CVE-2023-25564

Source
https://ubuntu.com/security/CVE-2023-25564
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-25564.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2023-25564
Related
Published
2023-02-14T18:15:00Z
Modified
2024-10-15T14:11:23Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H CVSS Calculator
Summary
[none]
Details

GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, memory corruption can be triggered when decoding UTF16 strings. The variable outlen was not initialized and could cause writing a zero to an arbitrary place in memory if ntlm_str_convert() were to fail, which would leave outlen uninitialized. This can lead to a denial of service if the write hits unmapped memory or randomly corrupts a byte in the application memory space. This vulnerability can trigger an out-of-bounds write, leading to memory corruption. This vulnerability can be triggered via the main gss_accept_sec_context entry point. This issue is fixed in version 1.2.0.

References

Affected packages

Ubuntu:Pro:16.04:LTS / gss-ntlmssp

Package

Name
gss-ntlmssp
Purl
pkg:deb/ubuntu/gss-ntlmssp?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.6.0-1
0.7.0-3~ubuntu0.16.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / gss-ntlmssp

Package

Name
gss-ntlmssp
Purl
pkg:deb/ubuntu/gss-ntlmssp?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.7.0-3
0.7.0-4
0.7.0-4build1
0.7.0-4build3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / gss-ntlmssp

Package

Name
gss-ntlmssp
Purl
pkg:deb/ubuntu/gss-ntlmssp?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.7.0-4build3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / gss-ntlmssp

Package

Name
gss-ntlmssp
Purl
pkg:deb/ubuntu/gss-ntlmssp?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.7.0-4build3
0.7.0-4build4

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / gss-ntlmssp

Package

Name
gss-ntlmssp
Purl
pkg:deb/ubuntu/gss-ntlmssp?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.2.0-1build3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / gss-ntlmssp

Package

Name
gss-ntlmssp
Purl
pkg:deb/ubuntu/gss-ntlmssp?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.2.0-1
1.2.0-1build1
1.2.0-1build2
1.2.0-1build3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}