CVE-2019-17266
—CVSS 3.1
9.8 critical
EPSS
3%p86
Published
()
Modified
Description
libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.
In the news0 stories
No ingested article mentions this CVE yet.