PT-2026-51567 · Gnu · Gnu Sasl
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GNU SASL versions prior to 2.2.4
Description
The NTLM client lacks sanitization of a short challenge within the
gsasl ntlm client step() function. This flaw allows a crafted server to cause memory disclosure.Recommendations
Update to version 2.2.4 or later.
Fix
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gnu Sasl