USN-7588-1

Source
https://ubuntu.com/security/notices/USN-7588-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7588-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-7588-1
Related
Published
2025-06-23T09:59:40.477572Z
Modified
2025-06-23T09:59:40.477572Z
Summary
gss-ntlmssp vulnerabilities
Details

Phil Turnbull discovered that GSS NTLMSSP may perform out-of-bounds reads when decoding NTLM fields and target information. An attacker could possibly use this issue to cause GSS NTLMSSP to crash, resulting in a denial of service. (CVE-2023-25563, CVE-2023-25567)

Phil Turnbull discovered that GSS NTLMSSP did not properly initialize memory when decoding UTF16 strings. An attacker could possibly use this issue to trigger an out-of-bounds write, resulting in a crash. (CVE-2023-25564)

Phil Turnbull discovered that GSS NTLMSSP did not properly handle memory cleanup. An attacker could possibly use this issue to cause an assertion failure, resulting in a denial of service. (CVE-2023-25565)

References

Affected packages

Ubuntu:Pro:16.04:LTS / gss-ntlmssp

Package

Name
gss-ntlmssp
Purl
pkg:deb/ubuntu/gss-ntlmssp@0.7.0-3~ubuntu0.16.04.1+esm1?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.7.0-3~ubuntu0.16.04.1+esm1

Affected versions

0.*

0.6.0-1
0.7.0-3~ubuntu0.16.04.1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "0.7.0-3~ubuntu0.16.04.1+esm1",
            "binary_name": "gss-ntlmssp"
        },
        {
            "binary_version": "0.7.0-3~ubuntu0.16.04.1+esm1",
            "binary_name": "gss-ntlmssp-dbgsym"
        },
        {
            "binary_version": "0.7.0-3~ubuntu0.16.04.1+esm1",
            "binary_name": "gss-ntlmssp-dev"
        }
    ]
}

Ubuntu:Pro:18.04:LTS / gss-ntlmssp

Package

Name
gss-ntlmssp
Purl
pkg:deb/ubuntu/gss-ntlmssp@0.7.0-4ubuntu0.18.04.1~esm1?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.7.0-4ubuntu0.18.04.1~esm1

Affected versions

0.*

0.7.0-3
0.7.0-4
0.7.0-4build1
0.7.0-4build3

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "0.7.0-4ubuntu0.18.04.1~esm1",
            "binary_name": "gss-ntlmssp"
        },
        {
            "binary_version": "0.7.0-4ubuntu0.18.04.1~esm1",
            "binary_name": "gss-ntlmssp-dbgsym"
        },
        {
            "binary_version": "0.7.0-4ubuntu0.18.04.1~esm1",
            "binary_name": "gss-ntlmssp-dev"
        }
    ]
}

Ubuntu:Pro:20.04:LTS / gss-ntlmssp

Package

Name
gss-ntlmssp
Purl
pkg:deb/ubuntu/gss-ntlmssp@0.7.0-4ubuntu0.20.04.1~esm1?arch=source&distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.7.0-4ubuntu0.20.04.1~esm1

Affected versions

0.*

0.7.0-4build3

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "0.7.0-4ubuntu0.20.04.1~esm1",
            "binary_name": "gss-ntlmssp"
        },
        {
            "binary_version": "0.7.0-4ubuntu0.20.04.1~esm1",
            "binary_name": "gss-ntlmssp-dbgsym"
        },
        {
            "binary_version": "0.7.0-4ubuntu0.20.04.1~esm1",
            "binary_name": "gss-ntlmssp-dev"
        }
    ]
}

Ubuntu:Pro:22.04:LTS / gss-ntlmssp

Package

Name
gss-ntlmssp
Purl
pkg:deb/ubuntu/gss-ntlmssp@0.7.0-4ubuntu0.22.04.1~esm1?arch=source&distro=esm-apps/jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.7.0-4ubuntu0.22.04.1~esm1

Affected versions

0.*

0.7.0-4build3
0.7.0-4build4

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "0.7.0-4ubuntu0.22.04.1~esm1",
            "binary_name": "gss-ntlmssp"
        },
        {
            "binary_version": "0.7.0-4ubuntu0.22.04.1~esm1",
            "binary_name": "gss-ntlmssp-dbgsym"
        },
        {
            "binary_version": "0.7.0-4ubuntu0.22.04.1~esm1",
            "binary_name": "gss-ntlmssp-dev"
        }
    ]
}