VYPR
Critical severity9.8NVD Advisory· Published Oct 6, 2019· Updated Jun 17, 2026

CVE-2019-17266

CVE-2019-17266

Description

libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:gnome:libsoup:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:gnome:libsoup:*:*:*:*:*:*:*:*range: >=2.65.1,<2.66.4
    • (no CPE)range: 2.65.1 - 2.68.1
  • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*+ 1 more
    • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
  • libsoup/libsoupdescription

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.