PT-2024-40608 · Poco · Poco

Published

2024-10-13

·

Updated

2024-10-13

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions: Poco (affected versions not specified)
Description: The issue is related to a crash caused by the use of an uninitialized value. The crash occurs in the Poco::Net::NTLMCredentials::parseChallengeMessage function, which is called by Poco::Net::HTTPNTLMCredentials::createNTLMMessage and Poco::Net::HTTPNTLMCredentials::authenticate.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

OSV-2024-1216

Affected Products

Poco