Security Advisory
CVE-2019-17266
9.8
CRITICAL
Vulnerability Description
libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.
Published Date
October 6, 2019
Official Source
NIST NVD Advisory