CVE-2019-17455: Critical severity nongnu Libntlm vulnerability
Published Oct 10, 2019
·Updated
Last updated 25 August 2025
Other sources
Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request.
— Launchpad
Affected Software
13 affected componentsFixes available
debian/libntlm<=1.5-2, <=1.5-1, <=1.4-8, <=1.4-3
1.6-11.4-3+deb8u1
nongnu Libntlm<=1.5
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=20.04
Fedoraproject Fedora=32
Fedoraproject Fedora=33
openSUSE Backports SLE=15.0-sp1
openSUSE Leap=15.1
debian/libntlm
1.6-31.6-41.8-41.8-6
Remediation
Event History
Oct 10, 2019
CVE Published
via MITRE·05:17 PM
Data Sourced
via MITRE·05:17 PM
Description
Feb 21, 2026
Data Sourced
via Debian·12:11 AM
DescriptionAffected Software
Data Sourced
via Ubuntu·12:11 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·12:12 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-17455?
CVE-2019-17455 is considered to have a medium severity due to the potential for stack-based buffer over-read vulnerabilities.
2
How do I fix CVE-2019-17455?
To fix CVE-2019-17455, upgrade libntlm to versions 1.6-1 or later.
3
Which software is affected by CVE-2019-17455?
CVE-2019-17455 affects libntlm versions up to and including 1.5.
4
Is CVE-2019-17455 exploitable remotely?
Yes, CVE-2019-17455 can be exploited remotely through crafted NTLM requests.
5
What platforms are impacted by CVE-2019-17455?
CVE-2019-17455 impacts various distributions including Debian, Ubuntu, and Fedora.