Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-17455

Опубликовано: 10 окт. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request.

РелизСтатусПримечание
bionic

released

1.4-8ubuntu0.1
devel

not-affected

1.6-1
disco

ignored

end of life
eoan

ignored

end of life
esm-apps/bionic

released

1.4-8ubuntu0.1
esm-apps/focal

released

1.5-2ubuntu0.1
esm-apps/jammy

not-affected

1.6-1
esm-apps/xenial

released

1.4-7ubuntu0.1~esm1
esm-infra-legacy/trusty

released

1.4-1ubuntu0.1~esm1
focal

released

1.5-2ubuntu0.1

Показывать по

EPSS

Процентиль: 88%
0.03934
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.1
redhat
почти 6 лет назад

Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request.

CVSS3: 9.8
nvd
почти 6 лет назад

Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request.

CVSS3: 9.8
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 9.8
debian
почти 6 лет назад

Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequ ...

suse-cvrf
около 5 лет назад

Security update for libntlm

EPSS

Процентиль: 88%
0.03934
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3