Packages
- gss-ntlmssp - A mechglue plugin for the GSSAPI library that implements NTLM authentication
Details
Phil Turnbull discovered that GSS NTLMSSP may perform out-of-bounds reads
when decoding NTLM fields and target information. An attacker could
possibly use this issue to cause GSS NTLMSSP to crash, resulting in
a denial of service. (CVE-2023-25563, CVE-2023-25567)
Phil Turnbull discovered that GSS NTLMSSP did not properly initialize
memory when decoding UTF16 strings. An attacker could possibly use
this issue to trigger an out-of-bounds write, resulting in a crash.
(CVE-2023-25564)
Phil Turnbull discovered that GSS NTLMSSP did not properly handle memory
cleanup. An attacker could possibly use this issue to cause an assertion
failure, resulting in a denial of service. (CVE-2023-25565)
Phil Turnbull discovered that GSS NTLMSSP may perform out-of-bounds reads
when decoding NTLM fields and target information. An attacker could
possibly use this issue to cause GSS NTLMSSP to crash, resulting in
a denial of service. (CVE-2023-25563, CVE-2023-25567)
Phil Turnbull discovered that GSS NTLMSSP did not properly initialize
memory when decoding UTF16 strings. An attacker could possibly use
this issue to trigger an out-of-bounds write, resulting in a crash.
(CVE-2023-25564)
Phil Turnbull discovered that GSS NTLMSSP did not properly handle memory
cleanup. An attacker could possibly use this issue to cause an assertion
failure, resulting in a denial of service. (CVE-2023-25565)
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
Ubuntu Release | Package Version | ||
---|---|---|---|
22.04 jammy | gss-ntlmssp – 0.7.0-4ubuntu0.22.04.1~esm1 | ||
20.04 focal | gss-ntlmssp – 0.7.0-4ubuntu0.20.04.1~esm1 | ||
18.04 bionic | gss-ntlmssp – 0.7.0-4ubuntu0.18.04.1~esm1 | ||
16.04 xenial | gss-ntlmssp – 0.7.0-3~ubuntu0.16.04.1+esm1 |
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.