Skip to content

Out-of-bounds read when decoding target information

Low
simo5 published GHSA-24pf-6prf-24ch Feb 12, 2023

Package

No package listed

Affected versions

<= 1.1.0

Patched versions

1.2.0

Description

Summary

An out-of-bounds read when decoding target information

Details

The length of the av_pair is not checked properly for two of the elements which can trigger an out-of-bound read.

Impact

The out-of-bounds read can be triggered via the main gss_accept_sec_context entry point and could cause a denial-of-service if the memory is unmapped.

Severity

Low

CVE ID

CVE-2023-25567

Weaknesses

Credits