VYPR
Critical severity9.8NVD Advisory· Published Oct 10, 2019· Updated Jun 17, 2026

CVE-2019-17455

CVE-2019-17455

Description

Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

15
  • cpe:2.3:a:nongnu:libntlm:*:*:*:*:*:*:*:*
    Range: <=1.5
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*+ 3 more
    • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
  • cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
  • cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
  • osv-coords2 versions
    < 1.6-bp151.4.3.1+ 1 more
    • (no CPE)range: < 1.6-bp151.4.3.1
    • (no CPE)range: < 1.6-lp151.3.3.1
  • libntlm/libntlmllm-fuzzy
    Range: <=1.5
  • Libntlm/Libntlmdescription

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.