Описание
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 2.2.4-1 |
| esm-apps-legacy/xenial | needs-triage | |
| esm-apps/bionic | needs-triage | |
| esm-apps/focal | needs-triage | |
| esm-apps/jammy | needs-triage | |
| esm-infra-legacy/trusty | needs-triage | |
| jammy | needs-triage | |
| noble | needs-triage | |
| questing | ignored | end of life, was needs-triage |
| resolute | needs-triage |
Показывать по
10
EPSS
Процентиль: 21%
0.00286
Низкий
3.7 Low
CVSS3
Связанные уязвимости
CVSS3: 3.7
nvd
около 1 месяца назад
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
CVSS3: 3.7
debian
около 1 месяца назад
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsas ...
CVSS3: 3.7
github
около 1 месяца назад
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
EPSS
Процентиль: 21%
0.00286
Низкий
3.7 Low
CVSS3