-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2021.4005
                          libntlm security update
                             29 November 2021

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           libntlm
Publisher:         Debian
Operating System:  Debian GNU/Linux
Impact/Access:     Execute Arbitrary Code/Commands -- Remote/Unauthenticated
                   Denial of Service               -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2019-17455  

Reference:         ESB-2021.3362
                   ESB-2020.1632

Original Bulletin: 
   https://lists.debian.org/debian-lts-announce/2021/11/msg00026.html

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- - -------------------------------------------------------------------------
Debian LTS Advisory DLA-2831-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                          Adrian Bunk
November 28, 2021                             https://wiki.debian.org/LTS
- - -------------------------------------------------------------------------

Package        : libntlm
Version        : 1.4-8+deb9u1
CVE ID         : CVE-2019-17455
Debian Bug     : 942145

Stack-based buffer over-reads for crafted NTLM requests were fixed in 
libntlm, a library that implements Microsoft's NTLM authentication.

For Debian 9 stretch, this problem has been fixed in version
1.4-8+deb9u1.

We recommend that you upgrade your libntlm packages.

For the detailed security status of libntlm please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libntlm

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
- -----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmGj1IoACgkQiNJCh6LY
mLHQBhAAl02afNlTzguUk/Nsg0T7VplmnKPKmUWhtNaawtjmuhFPNYDpmoyPT0TG
+Y5eY2CU7I9752FDCGGVrzG8OQKiUeDNFhAsd/oAFlquDS9CP7Gg0YRAMXU7FApZ
CUGOQnLn2XDUWWuvqzoN9DF4g1iRpZ/KWD4iIR8w55olHJT7KufgCeI6lvj+WYot
DxYLVa98I8q12mVgYmso8+2gO+hRs1Fn1pWdrOzkgfUYQW+PiYVq40TMjRADEoTB
XHXTk1VS9wMeyBFozUWB1ZQWkkIZ83BuTnOHJsVrSL0Qfjmwm+dGRRt7fs9NBX65
uxFQlcv7auIWKvhF7wY2WomPC+2xDk8CeZMf1KU4k9+CTT0C/K5V3YXaRF+FksJR
rhBL1x7xzBTHl47GLYWkFKH8XusVJyDGMbM5YddJtUQ/EgN1W6VEcaOtzDv28EH0
ot0ZN/CsVvrUGbBdaSzN4nvfYYN2UtXpQuiHKYi4qy7yAjC4jJwfAQCOrOX2MHDq
IcA0fzorryokVFsiIRIeVx7E9kCEO9d8jqcGMNjYL7CS39HKDEsQhoJ14tbjShyj
aEGvNhTFBamLtaQFYOG5TtsSKFG+i85gicVz+JFGxezS3aC51RF5328qAs8CG/ii
E6rV5AA8AlEY2aXBHEvObmBr98FgTVjMkFW6W7IrFT4Kx7d70Ok=
=H+Gs
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBYaQgVuNLKJtyKPYoAQgmJA//dCGXIqz25+7ggQjY1M3miOjaaH4Nb4nk
Wdo60XqaSxnTTfvkgLPFDp1fi/E+OnfVO+5BWU6rkfsQH6JtvTeY/eKOUT2DZTwY
Pp3qI8B6UBnHrHqfk2HdMhgTt/C3HGsHtIMfWhtSel11q3Il5uHDl/UesR3H6b9J
lmY1UQ8EFtELebqSjZRo5R/C64D/wmDT+EfgiTgCtcm+v+TFE2Y7MUf8fzEeKb2D
DF8KvQHgFOliapigtaEsDZCJH/C+qneXnV61WFfPxhK7yRZJY1YFYVimsbMz9Rz7
hATsmxQjUkcFKXNjKzFbiGAlF8BJWUYdCqEtey49KUCrlpMffVFct82XLKfuBPol
SaaBZ6f38ekjER9gYCVhviUfi9OBwdTbLORu4MLvNCyjY+qjRMrNSAEKaiG7lJqU
8IZxSb8lmBQaDNDiBPuWTaoCMKaAR2Ckxw3FUlOaXPbF6ieaOVVo/MwsaORtaPWg
7nfyNISxypiGUz5Vy18+h6okzhrjJZ8sH/vUavGAwXJPJb2jqINZQOxKeRFHbyof
SK3jHatGuByIwtGxJwj2dc+vGLPcgB4jkMpmABZbNzQe/pobwc9Muayv01Gp9EGn
xggFxfBU8CI3Y5I/ugRwtEgKF1DCPIETegvNnRgELRfDUFbPP3FQ5MaIu2mIoIt9
+2fFo36B3pI=
=8fmz
-----END PGP SIGNATURE-----