Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
go-ntlmssp NTLM challenges can panic on malformed payloads
Vulnerability Description
go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can causes an slice out of bounds panic, which can crash any Go process using `ntlmssp.Negotiator` as an HTTP transport. Version 0.1.1 patches the issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Vulnerability Type
整数溢出或超界折返
Vulnerability Title
go-ntlmssp 输入验证错误漏洞
Vulnerability Description
go-ntlmssp是Microsoft Azure开源的一个HTTP NTLM认证协议实现包。 go-ntlmssp 0.1.1之前版本存在输入验证错误漏洞,该漏洞源于恶意NTLM挑战消息可能导致切片越界恐慌,从而崩溃使用ntlmssp.Negotiator作为HTTP传输的Go进程。
CVSS Information
N/A
Vulnerability Type
N/A