CVE-2026-56968
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
Affected (2)
Products: Gnu: Sasl · Debian: Debian Linux
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 13.0 |
Related CWEs
CWE-839
Numeric Range Comparison Without Minimum Check
The product checks a value to ensure that it is less than or equal to a maximum, but it does not also verify that the value is greater than or equal to the minimum.
CWE-908
Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.
References (4)
Source: cve@mitre.org
Mailing List
Source: cve@mitre.org
ExploitMailing ListVendor Advisory
Timeline
No history available yet.