The ntlm_challenge function in the NTLM SASL authentication mechanism in camel/camel-sasl-ntlm.c in Camel in Evolution Data Server (aka evolution-data-server) 2.24.5 and earlier, and 2.25.92 and earlier 2.25.x versions, does not validate whether a certain length value is consistent with the amount of data in a challenge packet, which allows remote mail servers to read information from the process memory of a client, or cause a denial of service (client crash), via an NTLM authentication type 2 packet with a length value that exceeds the amount of packet data.
CVSS Details
- CVSS 3.1 Base Score: 4.2
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade evolution-data-server | Jul 30, 2024 | Mar 14, 2009 |
| Oracle_linux | — | Upgrade evolution-data-serverUpgrade evolution-data-server-develUpgrade evolution-data-server-doc | Oct 16, 2024 | Mar 14, 2009 |
| Suse | — | Upgrade evolution-data-server-32bitUpgrade evolution-data-server-x86Upgrade evolution-data-server-langUpgrade evolution-data-serverUpgrade gtkhtml2Upgrade gtkhtml2-lang | Feb 17, 2015 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub