{"id":"CVE-2019-17266","details":"libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.","modified":"2026-08-07T15:18:09.741584Z","published":"2019-10-06T22:15:10.367Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"18.04"},{"last_affected":"18.04"},{"introduced":"19.04"},{"last_affected":"19.04"}],"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux"}]},"references":[{"type":"WEB","url":"https://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg1705054.html"},{"type":"ADVISORY","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=941912"},{"type":"ADVISORY","url":"https://github.com/Kirin-say/Vulnerabilities/blob/master/CVE-2019-17266_POC.md"},{"type":"ADVISORY","url":"https://gitlab.gnome.org/GNOME/libsoup/commit/88b7dff4467f4151afae244ea7d1223753cd05ab"},{"type":"ADVISORY","url":"https://gitlab.gnome.org/GNOME/libsoup/commit/f8a54ac85eec2008c85393f331cdd251af8266ad"},{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2019-17266"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4152-1/"},{"type":"REPORT","url":"https://gitlab.gnome.org/GNOME/libsoup/issues/173"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gnome/libsoup","events":[{"introduced":"f880a4a2de0f6e8ecfbe23078c71f1409f9a1b5d"},{"fixed":"bdcf906745379df9d490bb214374512b84d5e8da"},{"introduced":"24592981d6089b66968720f37825c8e45ae628a0"},{"last_affected":"15a3d17bdefebede9262933752a897cf51976a05"}],"database_specific":{"cpe":"cpe:2.3:a:gnome:libsoup:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.65.1"},{"fixed":"2.66.4"},{"introduced":"2.67.1"},{"last_affected":"2.68.1"}],"source":"CPE_RANGE"}}],"versions":["2.66.3","2.68.1","2.68.0","2.67.93","2.67.92","2.67.91","2.67.90","2.67.3","2.67.2","2.67.1","2.66.2","2.66.1","2.66.0","2.65.92","2.65.91","2.65.90","2.65.2","2.65.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-17266.json"}},{"ranges":[{"type":"GIT","repo":"https://gitlab.gnome.org/gnome/libsoup","events":[{"introduced":"f880a4a2de0f6e8ecfbe23078c71f1409f9a1b5d"},{"fixed":"bdcf906745379df9d490bb214374512b84d5e8da"},{"introduced":"24592981d6089b66968720f37825c8e45ae628a0"},{"last_affected":"15a3d17bdefebede9262933752a897cf51976a05"},{"fixed":"88b7dff4467f4151afae244ea7d1223753cd05ab"},{"fixed":"f8a54ac85eec2008c85393f331cdd251af8266ad"}],"database_specific":{"extracted_events":[{"introduced":"2.65.1"},{"fixed":"2.66.4"},{"introduced":"2.67.1"},{"last_affected":"2.68.1"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:gnome:libsoup:*:*:*:*:*:*:*:*"}}],"versions":["2.66.3","2.68.1","2.68.0","2.67.93","2.67.92","2.67.91","2.67.90","2.67.3","2.67.2","2.67.1","2.66.2","2.66.1","2.66.0","2.65.92","2.65.91","2.65.90","2.65.2","2.65.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-17266.json","vanir_signatures_modified":"2026-08-07T15:18:09Z","vanir_signatures":[{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["14331469025586231543591114824372293487","105098998331837764232321155729018717892","266396959809182485889246480568975055349","225325912854221928613598010904794245346"]},"id":"CVE-2019-17266-5fb3d2ee","signature_type":"Line","signature_version":"v1","source":"https://gitlab.gnome.org/gnome/libsoup@88b7dff4467f4151afae244ea7d1223753cd05ab","target":{"file":"libsoup/soup-auth-ntlm.c"}},{"digest":{"threshold":0.9,"line_hashes":["14331469025586231543591114824372293487","105098998331837764232321155729018717892","266396959809182485889246480568975055349","225325912854221928613598010904794245346"]},"id":"CVE-2019-17266-7aac81ba","signature_type":"Line","signature_version":"v1","source":"https://gitlab.gnome.org/gnome/libsoup@f8a54ac85eec2008c85393f331cdd251af8266ad","target":{"file":"libsoup/soup-auth-ntlm.c"},"deprecated":false},{"id":"CVE-2019-17266-88394bd3","signature_type":"Function","signature_version":"v1","source":"https://gitlab.gnome.org/gnome/libsoup@88b7dff4467f4151afae244ea7d1223753cd05ab","target":{"file":"libsoup/soup-auth-ntlm.c","function":"soup_ntlm_parse_challenge"},"deprecated":false,"digest":{"function_hash":"22872420392307703907202346827715479280","length":1524}},{"deprecated":false,"digest":{"function_hash":"22872420392307703907202346827715479280","length":1524},"id":"CVE-2019-17266-9543589d","signature_type":"Function","signature_version":"v1","source":"https://gitlab.gnome.org/gnome/libsoup@f8a54ac85eec2008c85393f331cdd251af8266ad","target":{"file":"libsoup/soup-auth-ntlm.c","function":"soup_ntlm_parse_challenge"}}]}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}