VDB
Sign up
MEDIUM5.3

GHSA-pjcq-xvwq-hhpj

go-ntlmssp NTLM challenges can panic on malformed payloads

Quick fix

GHSA-pjcq-xvwq-hhpj — github.com/Azure/go-ntlmssp: upgrade to the fixed version with the command below.

go get github.com/Azure/go-ntlmssp@v0.1.1

Details

go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can causes an slice out of bounds panic, which can crash any Go process using `ntlmssp.Negotiator` as an HTTP transport. Version 0.1.1 patches the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/Azure/go-ntlmssp
Introduced in: 0Fixed in: 0.1.1
Fixgo get github.com/Azure/go-ntlmssp@v0.1.1

References