CVE-2023-25564 | GSS-NTLMSSP up to 1.1.x NTLM Authentication ntlm_str_convert outlen out-of-bounds write (GHSA-r85x-q5px-9xfq / Nessus ID 240491)
A vulnerability classified as critical was found in GSS-NTLMSSP up to 1.1.x. Affected by this issue is the function ntlm_str_convert of the component NTLM Authentication. The manipulation of the argument outlen results in out-of-bounds write.
This vulnerability is identified as CVE-2023-25564. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.