PT-2019-6101 · Libntlm+5 · Libntlm+5
Published
2019-10-08
·
Updated
2025-06-24
·
CVE-2019-17455
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
libntlm versions through 1.5
Description
The issue is related to a buffer over-read in the libntlm library, which implements the NT LAN Manager (NTLM) network authentication protocol. This can be exploited by a remote attacker to execute arbitrary code or cause a denial of service. The vulnerability is demonstrated by a stack-based buffer over-read in the buildSmbNtlmAuthRequest function in smbutil.c for a crafted NTLM request.
Recommendations
For libntlm versions through 1.5, consider applying a patch or updating to a version that fixes the buffer over-read issue in the buildSmbNtlmAuthRequest function. As a temporary workaround, restrict the use of the libntlm library for NTLM authentication to minimize the risk of exploitation.
Exploit
Fix
Stack Overflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Red Os
Suse
Ubuntu
Libntlm