PT-2019-6101 · Libntlm+5 · Libntlm+5
CVE-2019-17455
·
Publicado
2019-10-08
·
Atualizado
2025-06-24
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
libntlm versions through 1.5
Description
The issue is related to a buffer over-read in the libntlm library, which implements the NT LAN Manager (NTLM) network authentication protocol. This can be exploited by a remote attacker to execute arbitrary code or cause a denial of service. The vulnerability is demonstrated by a stack-based buffer over-read in the buildSmbNtlmAuthRequest function in smbutil.c for a crafted NTLM request.
Recommendations
For libntlm versions through 1.5, consider applying a patch or updating to a version that fixes the buffer over-read issue in the buildSmbNtlmAuthRequest function. As a temporary workaround, restrict the use of the libntlm library for NTLM authentication to minimize the risk of exploitation.
Exploit
Correção
Stack Overflow
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Linuxmint
Red Os
Suse
Ubuntu
Libntlm