GSS-NTLMSSP, a mechglue plugin for the GSSAPI library that implements NTLM authentication, has an out-of-bounds read when decoding target information prior to version 1.2.0. The length of the av_pair
is not checked properly for two of the elements which can trigger an out-of-bound read. The out-of-bounds read can be triggered via the main gss_accept_sec_context
entry point and could cause a denial-of-service if the memory is unmapped. The issue is fixed in version 1.2.0.
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_name": "gss-ntlmssp", "binary_version": "0.7.0-3~ubuntu0.16.04.1+esm1" }, { "binary_name": "gss-ntlmssp-dbgsym", "binary_version": "0.7.0-3~ubuntu0.16.04.1+esm1" }, { "binary_name": "gss-ntlmssp-dev", "binary_version": "0.7.0-3~ubuntu0.16.04.1+esm1" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_name": "gss-ntlmssp", "binary_version": "0.7.0-4ubuntu0.18.04.1~esm1" }, { "binary_name": "gss-ntlmssp-dbgsym", "binary_version": "0.7.0-4ubuntu0.18.04.1~esm1" }, { "binary_name": "gss-ntlmssp-dev", "binary_version": "0.7.0-4ubuntu0.18.04.1~esm1" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_name": "gss-ntlmssp", "binary_version": "0.7.0-4ubuntu0.20.04.1~esm1" }, { "binary_name": "gss-ntlmssp-dbgsym", "binary_version": "0.7.0-4ubuntu0.20.04.1~esm1" }, { "binary_name": "gss-ntlmssp-dev", "binary_version": "0.7.0-4ubuntu0.20.04.1~esm1" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_name": "gss-ntlmssp", "binary_version": "0.7.0-4ubuntu0.22.04.1~esm1" }, { "binary_name": "gss-ntlmssp-dbgsym", "binary_version": "0.7.0-4ubuntu0.22.04.1~esm1" }, { "binary_name": "gss-ntlmssp-dev", "binary_version": "0.7.0-4ubuntu0.22.04.1~esm1" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_name": "gss-ntlmssp", "binary_version": "1.2.0-1build3" }, { "binary_name": "gss-ntlmssp-dbgsym", "binary_version": "1.2.0-1build3" }, { "binary_name": "gss-ntlmssp-dev", "binary_version": "1.2.0-1build3" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_name": "gss-ntlmssp", "binary_version": "1.2.0-1build3" }, { "binary_name": "gss-ntlmssp-dbgsym", "binary_version": "1.2.0-1build3" }, { "binary_name": "gss-ntlmssp-dev", "binary_version": "1.2.0-1build3" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_name": "gss-ntlmssp", "binary_version": "1.2.0-1build3" }, { "binary_name": "gss-ntlmssp-dbgsym", "binary_version": "1.2.0-1build3" }, { "binary_name": "gss-ntlmssp-dev", "binary_version": "1.2.0-1build3" } ] }