CVE-2023-25564 | GSS-NTLMSSP up to 1.1.x NTLM Authentication ntlm_str_convert outlen out-of-bounds write (GHSA-r85x-q5px-9xfq / Nessus ID 240491)
A vulnerability was found in GSS-NTLMSSP up to 1.1.x. It has been declared as critical. Affected by this vulnerability is the function ntlm_str_convert of the component NTLM Authentication. The manipulation of the argument outlen leads to out-of-bounds write.
This vulnerability is known as CVE-2023-25564. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.