Out-of-bounds write in Gss-ntlmssp - CVE-2023-25564
Published: May 16, 2023
Gss-ntlmssp
modauthgssapi
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary in the ntlm_str_convert() function error when decoding UTF16 strings. A remote attacker can send specially crafted NTLM request to the application, trigger an out-of-bounds write error and perform a denial of service (DoS) attack.