PT-2023-20161 · Unknown+6 · Gss-Ntlmssp+6

Philipturnbull

·

Published

2023-02-12

·

Updated

2025-12-01

·

CVE-2023-25563

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GSS-NTLMSSP versions prior to 1.2.0
Description GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Multiple out-of-bounds reads when decoding NTLM fields can trigger a denial of service. A 32-bit integer overflow condition can lead to incorrect checks of consistency of length of internal buffers. This vulnerability can be triggered via the main gss accept sec context entry point if the application allows tokens greater than 4GB in length, leading to a large, up to 65KB, out-of-bounds read which could cause a denial-of-service if it reads from unmapped memory.
Recommendations For versions prior to 1.2.0, update to version 1.2.0 to patch the out-of-bounds reads. As a temporary workaround, consider restricting the application to accept tokens less than 4GB in length to minimize the risk of exploitation.

Exploit

Fix

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALSA-2023:3097
AZL-43480
AZL-44733
BDU:2025-12443
CESA-2023_3097
CVE-2023-25563
GHSA-JJJX-5QF7-9MGF
MGASA-2023-0108
OPENSUSE-SU-2023:0048-1
OPENSUSE-SU-2024:12701-1
RHSA-2023:3097
RHSA-2023_3097
USN-7588-1

Affected Products

Almalinux
Centos
Debian
Gss-Ntlmssp
Linuxmint
Red Hat
Ubuntu