Stack-based buffer over-reads for crafted NTLM requests were fixed in libntlm, a library that implements Microsoft's NTLM authentication. For Debian 9 stretch, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2831-1
libntlm could be made to crash or possibly execute arbitrary code.. =========================================================================Ubuntu Security Notice USN-5108-1 October 08, 2021 libntlm vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: libntlm could be made to crash or possibly execute arbitrary code. Software Description: - libntlm: NTLM authentication library Details: It was discovered that Libntlm incorrectly handled specially crafted NTML requests. An attacker could possibly use this issue to cause a denial of service or another unspecified impact. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: libntlm0 1.5-2ubuntu0.1 Ubuntu 18.04 LTS: libntlm0 1.4-8ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5108-1 CVE-2019-17455 Package Information: https://launchpad.net/ubuntu/+source/libntlm/1.5-2ubuntu0.1 https://launchpad.net/ubuntu/+source/libntlm/1.4-8ubuntu0.1 . Debian Security Bulletin DSN-4509-1 reveals a vulnerability in libxyz, posing risks of service disruption and code execution. Update your system promptly. libntlm Vulnerability, Denial of Service, Ubuntu Security Notice. . LinuxSecurity.com Team
Update to security fix 1.6 version. Fixes CVE-2019-17455. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-1f643c272c 2021-02-19 01:14:39.900954 --------------------------------------------------------------------------------Name : libntlm Product : Fedora 32 Version : 1.6 Release : 1.fc32 URL : http://www.nongnu.org/libntlm/ Summary : NTLMv1 authentication library Description : A library for authenticating with Microsoft NTLMV1 challenge-response, derived from Samba sources. --------------------------------------------------------------------------------Update Information: Update to security fix 1.6 version. Fixes CVE-2019-17455 --------------------------------------------------------------------------------ChangeLog: * Sat Oct 31 2020 Kevin Fenzi - 1.6-1 - Update to 1.6. Fixes CVE-2019-17455 * Sat Aug 1 2020 Fedora Release Engineering - 1.5-4 - Second attempt - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild * Tue Jul 28 2020 Fedora Release Engineering - 1.5-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1768464 - CVE-2019-17455 libntlm: stack-based buffer overflow in buildSmbNtlmAuthRequest in smbutil.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1768464 [ 2 ] Bug #1825591 - libntlm-1.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=1825591 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-1f643c272c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to security fix 1.6 version. Fixes CVE-2019-17455. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-8794383d6f 2021-01-21 01:44:43.057144 --------------------------------------------------------------------------------Name : libntlm Product : Fedora 33 Version : 1.6 Release : 1.fc33 URL : Summary : NTLMv1 authentication library Description : A library for authenticating with Microsoft NTLMV1 challenge-response, derived from Samba sources. --------------------------------------------------------------------------------Update Information: Update to security fix 1.6 version. Fixes CVE-2019-17455 --------------------------------------------------------------------------------ChangeLog: * Sat Oct 31 2020 Kevin Fenzi - 1.6-1 - Update to 1.6. Fixes CVE-2019-17455 --------------------------------------------------------------------------------References: [ 1 ] Bug #1768464 - CVE-2019-17455 libntlm: stack-based buffer overflow in buildSmbNtlmAuthRequest in smbutil.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1768464 [ 2 ] Bug #1825591 - libntlm-1.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=1825591 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-8794383d6f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for libntlm ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0806-1 Rating: moderate References: #1153669 Cross-References: CVE-2019-17455 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libntlm fixes the following issues: Update to release 1.6: * CVE-2019-17455: Fixed a buffer overflow in buildSmbNtlmAuth* function. (boo#1153669) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-806=1 Package List: - openSUSE Leap 15.1 (x86_64): libntlm-debugsource-1.6-lp151.3.3.1 libntlm-devel-1.6-lp151.3.3.1 libntlm0-1.6-lp151.3.3.1 libntlm0-debuginfo-1.6-lp151.3.3.1 References: https://www.suse.com/security/cve/CVE-2019-17455.html https://bugzilla.suse.com/1153669 -- . The latest update from openSUSE provides an essential fix for libntlm, tackling vulnerabilities linked to buffer overflow problems.. openSUSE, libntlm, security update, buffer overflow. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for libntlm ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0816-1 Rating: moderate References: #1153669 Cross-References: CVE-2019-17455 Affected Products: openSUSE Backports SLE-15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libntlm fixes the following issues: Update to release 1.6: * CVE-2019-17455: Fixed a buffer overflow in buildSmbNtlmAuth* function. (boo#1153669) This update was imported from the openSUSE:Leap:15.1:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP1: zypper in -t patch openSUSE-2020-816=1 Package List: - openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64): libntlm-devel-1.6-bp151.4.3.1 libntlm0-1.6-bp151.4.3.1 References: https://www.suse.com/security/cve/CVE-2019-17455.html https://bugzilla.suse.com/1153669 -- . This Arch Linux patch resolves a significant memory leak vulnerability in libcurl, improving overall security.. openSUSE, libntlm, security update, buffer overflow. . Severity: Important. LinuxSecurity.com Team
Updated libntlm packages fix security vulnerability: It was discovered that libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer . MGASA-2020-0219 - Updated libntlm packages fix security vulnerability Publication date: 24 May 2020 URL: https://advisories.mageia.org/MGASA-2020-0219.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-17455 Updated libntlm packages fix security vulnerability: It was discovered that libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request (CVE-2019-17455). References: - https://bugs.mageia.org/show_bug.cgi?id=26609 - https://lists.debian.org/debian-lts-announce/2020/05/msg00010.html - https://www.cve.org/CVERecord?id=CVE-2019-17455 SRPMS: - 7/core/libntlm-1.6-1.mga7 . A crucial security patch for libntlm resolves significant buffer overflow vulnerabilities present in Mageia distributions. Further information and sources are provided.. libntlm update, Mageia security, buffer overflow fix, security patch. . Severity: Critical. LinuxSecurity.com Team
It was discovered that libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse . Package : libntlm Version : 1.4-3+deb8u1 CVE ID : CVE-2019-17455 It was discovered that libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request. For Debian 8 "Jessie", this problem has been fixed in version 1.4-3+deb8u1. We recommend that you upgrade your libntlm packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Update the libntlm library on Debian LTS to address a serious buffer overflow vulnerability that may result in authentication errors.. libntlm, buffer overflow, debian security, authentication flaw. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.