GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
References
Configurations
No configuration.
History
23 Jun 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-23 17:17
Updated : 2026-06-25 20:16
NVD link : CVE-2026-56968
Mitre link : CVE-2026-56968
CVE.ORG link : CVE-2026-56968
JSON object : View
Products Affected
No product.
CWE
CWE-839
Numeric Range Comparison Without Minimum Check
