PT-2019-6101 · Libntlm+5 · Libntlm+5

Published

2019-10-08

·

Updated

2025-06-24

·

CVE-2019-17455

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libntlm versions through 1.5
Description The issue is related to a buffer over-read in the libntlm library, which implements the NT LAN Manager (NTLM) network authentication protocol. This can be exploited by a remote attacker to execute arbitrary code or cause a denial of service. The vulnerability is demonstrated by a stack-based buffer over-read in the buildSmbNtlmAuthRequest function in smbutil.c for a crafted NTLM request.
Recommendations For libntlm versions through 1.5, consider applying a patch or updating to a version that fixes the buffer over-read issue in the buildSmbNtlmAuthRequest function. As a temporary workaround, restrict the use of the libntlm library for NTLM authentication to minimize the risk of exploitation.

Exploit

Fix

Stack Overflow

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALT-PU-2025-5036
ALT-PU-2025-5046
AZL-7266
BDU:2021-05383
CVE-2019-17455
DLA-2207-1
DLA-2831-1
MGASA-2020-0219
OPENSUSE-SU-2020:0806-1
OPENSUSE-SU-2020:0816-1
OPENSUSE-SU-2020_0806-1
OPENSUSE-SU-2024:10963-1
USN-5108-1
USN-5108-2

Affected Products

Alt Linux
Linuxmint
Red Os
Suse
Ubuntu
Libntlm