{"id":"MGASA-2023-0108","summary":"Updated gssntlmssp packages fix security vulnerability","details":"Multiple out-of-bounds read when decoding NTLM fields. (CVE-2023-25563)\nMemory corruption when decoding UTF16 strings. (CVE-2023-25564)\nIncorrect free when decoding target information. (CVE-2023-25565)\nMemory leak when parsing usernames. (CVE-2023-25566)\nOut-of-bounds read when decoding target information. (CVE-2023-25567)\n","modified":"2026-04-16T04:42:19.226238144Z","published":"2023-03-24T05:55:49Z","upstream":["CVE-2023-25563","CVE-2023-25564","CVE-2023-25565","CVE-2023-25566","CVE-2023-25567"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2023-0108.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=31574"},{"type":"WEB","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WXCOTOTL4ZIZB65QEGM65YZZILOED4A3/"}],"affected":[{"package":{"name":"gssntlmssp","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/gssntlmssp?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.0-1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2023-0108.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}