Total vulnerabilities in the database
libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.
Software | From | Fixed in |
---|---|---|
gnome / libsoup | 2.67.1 | 2.68.1.x |
gnome / libsoup | 2.65.1 | 2.66.4 |
canonical / ubuntu_linux | 18.04 | 18.04.x |
canonical / ubuntu_linux | 19.04 | 19.04.x |