n0o.com - Personal archive of discovered vulns & writeups.

[CVE-2018-16890] NTLM type-2 out-of-bounds buffer read


Reported on : 31 Dec 2018 Shipped on : 6 Feb 2019 Type : OOB Access - Read - Send to Remote In Function : ntlm_decode_type2_target libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a malicious or broken NTLM server could trick libcurl to accept a bad length + offset combination that would lead to a buffer read out-of-bounds.
https://curl.haxx.se/docs/CVE-2018-16890.html

PENDING