CVE-2017-11103
published 2017-07-13CVE-2017-11103: Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates…
high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | < 11.0 | 11.0 |
| apple | mac_os_x | < 10.13.1 | 10.13.1 |
| apple | macos_high_sierra | — | — |
| apple | macos_high_sierra_10.13.1_security_update_2017-001_sierra_and_security_update_20 | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | heimdal | < heimdal 7.4.0.dfsg.1-1 (bookworm) | heimdal 7.4.0.dfsg.1-1 (bookworm) |
| debian | samba | < heimdal 7.4.0.dfsg.1-1 (bookworm) | heimdal 7.4.0.dfsg.1-1 (bookworm) |
| heimdal_project | heimdal | < 7.4.0 | 7.4.0 |
| heimdal_project | heimdal | >= 0 < 7.4.0.dfsg.1-1 | 7.4.0.dfsg.1-1 |
| heimdal_project | heimdal | >= 0 < 7.4.0.dfsg.1-1 | 7.4.0.dfsg.1-1 |
| heimdal_project | heimdal | >= 0 < 7.4.0.dfsg.1-1 | 7.4.0.dfsg.1-1 |
| heimdal_project | heimdal | >= 0 < 7.4.0.dfsg.1-1 | 7.4.0.dfsg.1-1 |
| samba | samba | >= 0 < 2:4.6.5+dfsg-4 | 2:4.6.5+dfsg-4 |
| samba | samba | >= 0 < 2:4.6.5+dfsg-4 | 2:4.6.5+dfsg-4 |
| samba | samba | >= 0 < 2:4.6.5+dfsg-4 | 2:4.6.5+dfsg-4 |
| samba | samba | >= 0 < 2:4.6.5+dfsg-4 | 2:4.6.5+dfsg-4 |
| samba | samba | >= 4.0.0 < 4.4.15 | 4.4.15 |
| samba | samba | >= 4.5.0 < 4.5.12 | 4.5.12 |
| samba | samba | >= 4.6.0 < 4.6.6 | 4.6.6 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH