• 公告ID (KylinSec-SA-2023-1100)

摘要:

GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, a memory leak can be triggered when parsing usernames which can trigger a denial-of-service. The domain portion of a username may be overridden causing an allocated memory area the size of the domain name to be leaked. An attacker can leak memory via the main `gss_accept_sec_context` entry point, potentially causing a denial-of-service. This issue is fixed in version 1.2.0.

安全等级: Low

公告ID: KylinSec-SA-2023-1100

发布日期: 2023年2月27日

关联CVE: CVE-2023-25566  

  • 详细介绍

1. 漏洞描述

   

GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, a memory leak can be triggered when parsing usernames which can trigger a denial-of-service. The domain portion of a username may be overridden causing an allocated memory area the size of the domain name to be leaked. An attacker can leak memory via the main `gss_accept_sec_context` entry point, potentially causing a denial-of-service. This issue is fixed in version 1.2.0.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2023-25566 KY3.4-4A gssntlmssp Unaffected
CVE-2023-25566 KY3.4-5A gssntlmssp Unaffected
CVE-2023-25566 KY3.5.1 gssntlmssp Unaffected
CVE-2023-25566 KY3.5.2 gssntlmssp Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2023-1099 下一篇:KylinSec-SA-2023-1101