Out-of-bounds write in Gss-ntlmssp - CVE-2023-25564
Published: May 16, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary in the ntlm_str_convert() function error when decoding UTF16 strings. A remote attacker can send specially crafted NTLM request to the application, trigger an out-of-bounds write error and perform a denial of service (DoS) attack.
Affected software
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Ubuntu
openEuler
gss-ntlmssp (Ubuntu package)
gssntlmssp
gssntlmssp-debuginfo
gssntlmssp-devel
gssntlmssp-help
gssntlmssp-debugsource
gssntlmssp (Red Hat package)
gssntlmssp-doc
How to mitigate CVE-2023-25564
gss-ntlmssp (Ubuntu package) - addressed in versions 0.7.0-3~ubuntu0.16.04.1+esm1, 0.7.0-4ubuntu0.18.04.1~esm1, 0.7.0-4ubuntu0.20.04.1~esm1, 0.7.0-4ubuntu0.22.04.1~esm1
gssntlmssp - update to 0.7.0-9
gssntlmssp-debuginfo - update to 0.7.0-9
gssntlmssp-devel - update to 0.7.0-9
gssntlmssp-help - update to 0.7.0-9
gssntlmssp-debugsource - update to 0.7.0-9
gssntlmssp - addressed in versions 1.2.0-1.el7, 1.2.0-1.fc37
gssntlmssp (Red Hat package) - update to 1.2.0-1.el8_8
gssntlmssp - update to 1.2.0-1.0.1
gssntlmssp-doc - update to 1.2.0-1.0.1