CVE-2019-17266 in GNOME and Canonical Products
Published on October 6, 2019
libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.
Products Associated with CVE-2019-17266
stack.watch emails you whenever new vulnerabilities are published in GNOME Libsoup or Canonical Ubuntu Linux. Just hit a watch button to start following.
Exploit Probability
EPSS
0.94%
Percentile
76.07%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.