Vulnerability CVE-2019-17266: Information
Description
libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.
Severity: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
libsoup | sisyphus | 2.68.2-alt1 | 2.74.3-alt1.1 | ALT-PU-2019-2849-1 | 238952 | Fixed |
libsoup | p10 | 2.68.2-alt1 | 2.74.1-alt1 | ALT-PU-2019-2849-1 | 238952 | Fixed |
libsoup | c10f1 | 2.68.2-alt1 | 2.74.1-alt1 | ALT-PU-2019-2849-1 | 238952 | Fixed |
libsoup | c9f2 | 2.66.2-alt1.c9f2.1 | 2.66.2-alt1.c9f2.1 | ALT-PU-2022-3170-1 | 309774 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://gitlab.gnome.org/GNOME/libsoup/issues/173 |
|
https://security-tracker.debian.org/tracker/CVE-2019-17266 |
|
https://gitlab.gnome.org/GNOME/libsoup/commit/88b7dff4467f4151afae244ea7d1223753cd05ab |
|
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=941912 |
|
https://github.com/Kirin-say/Vulnerabilities/blob/master/CVE-2019-17266_POC.md |
|
https://gitlab.gnome.org/GNOME/libsoup/commit/f8a54ac85eec2008c85393f331cdd251af8266ad |
|
USN-4152-1 |
|
https://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg1705054.html |