gnome libsoup CVE-2019-17266 in GNOME and Canonical Products
Published on October 6, 2019

product logo product logo
libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.

Vendor Advisory NVD


Products Associated with CVE-2019-17266

stack.watch emails you whenever new vulnerabilities are published in GNOME Libsoup or Canonical Ubuntu Linux. Just hit a watch button to start following.

 
 

Exploit Probability

EPSS
0.94%
Percentile
76.07%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.