GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 3
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Gnu Sasl
cpe:2.3:a:gnu:sasl:*:*:*:*:*:*:*:*
|
— |
2.2.4
|
|
Debian Debian_Linux
cpe:2.3:o:debian:debian_linux:13.0:*:*:*:*:*:*:*
|
— | — |
|
Gnu Gnu_Sasl
cpe:2.3:a:gnu:gnu_sasl:*:*:*:*:*:*:*:*
|
— |
2.2.4
|