Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-17266

libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 74.7%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
References
Products affected by CVE-2019-17266
  • Gnome » Libsoup » Version: 2.65.1
    cpe:2.3:a:gnome:libsoup:2.65.1
  • Gnome » Libsoup » Version: 2.65.2
    cpe:2.3:a:gnome:libsoup:2.65.2
  • Gnome » Libsoup » Version: 2.65.90
    cpe:2.3:a:gnome:libsoup:2.65.90
  • Gnome » Libsoup » Version: 2.65.91
    cpe:2.3:a:gnome:libsoup:2.65.91
  • Gnome » Libsoup » Version: 2.65.92
    cpe:2.3:a:gnome:libsoup:2.65.92
  • Gnome » Libsoup » Version: 2.66
    cpe:2.3:a:gnome:libsoup:2.66
  • Gnome » Libsoup » Version: 2.66.0
    cpe:2.3:a:gnome:libsoup:2.66.0
  • Gnome » Libsoup » Version: 2.66.1
    cpe:2.3:a:gnome:libsoup:2.66.1
  • Gnome » Libsoup » Version: 2.66.2
    cpe:2.3:a:gnome:libsoup:2.66.2
  • Gnome » Libsoup » Version: 2.66.3
    cpe:2.3:a:gnome:libsoup:2.66.3
  • Gnome » Libsoup » Version: 2.67.1
    cpe:2.3:a:gnome:libsoup:2.67.1
  • Gnome » Libsoup » Version: 2.67.2
    cpe:2.3:a:gnome:libsoup:2.67.2
  • Gnome » Libsoup » Version: 2.67.3
    cpe:2.3:a:gnome:libsoup:2.67.3
  • Gnome » Libsoup » Version: 2.67.90
    cpe:2.3:a:gnome:libsoup:2.67.90
  • Gnome » Libsoup » Version: 2.67.91
    cpe:2.3:a:gnome:libsoup:2.67.91
  • Gnome » Libsoup » Version: 2.67.92
    cpe:2.3:a:gnome:libsoup:2.67.92
  • Gnome » Libsoup » Version: 2.67.93
    cpe:2.3:a:gnome:libsoup:2.67.93
  • Gnome » Libsoup » Version: 2.68.0
    cpe:2.3:a:gnome:libsoup:2.68.0
  • Gnome » Libsoup » Version: 2.68.1
    cpe:2.3:a:gnome:libsoup:2.68.1
  • Canonical » Ubuntu Linux » Version: 18.04
    cpe:2.3:o:canonical:ubuntu_linux:18.04
  • Canonical » Ubuntu Linux » Version: 19.04
    cpe:2.3:o:canonical:ubuntu_linux:19.04


Contact Us

Shodan ® - All rights reserved