CVE-2017-17439
published 2017-12-06CVE-2017-17439: In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet containing empty data fields for client name…
PriorityP343high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
3.43%
87.6th percentile
In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet containing empty data fields for client name or realm. The parser would unconditionally dereference NULL pointers in that case, leading to a segmentation fault. This is related to the _kdc_as_rep function in kdc/kerberos5.c and the der_length_visible_string function in lib/asn1/der_length.c.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | heimdal | < heimdal 7.5.0+dfsg-1 (bookworm) | heimdal 7.5.0+dfsg-1 (bookworm) |
| heimdal_project | heimdal | <= 7.4.0 | — |
| heimdal_project | heimdal | >= 0 < 7.5.0+dfsg-1 | 7.5.0+dfsg-1 |
| heimdal_project | heimdal | >= 0 < 7.5.0+dfsg-1 | 7.5.0+dfsg-1 |
| heimdal_project | heimdal | >= 0 < 7.5.0+dfsg-1 | 7.5.0+dfsg-1 |
| heimdal_project | heimdal | >= 0 < 7.5.0+dfsg-1 | 7.5.0+dfsg-1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2017-17439: heimdal - In Heimdal through 7.4, remote unauthenticated attackers are able to crash the K...
vendor_debian·2017·CVSS 7.5
CVE-2017-17439 [HIGH] CVE-2017-17439: heimdal - In Heimdal through 7.4, remote unauthenticated attackers are able to crash the K...
In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet containing empty data fields for client name or realm. The parser would unconditionally dereference NULL pointers in that case, leading to a segmentation fault. This is related to the _kdc_as_rep function in kdc/kerberos5.c and the der_length_visible_string function in lib/asn1/der_length.c.
Scope: local
bookworm: resolved (fixed in 7.5.0+dfsg-1)
bullseye: resolved (fixed in 7.5.0+dfsg-1)
forky: resolved (fixed in 7.5.0+dfsg-1)
sid: resolved (fixed in 7.5.0+dfsg-1)
trixie: resolved (fixed in 7.5.0+dfsg-1)
GHSA
GHSA-gc5p-r2vh-qc88: In Heimdal through 7
ghsa_unreviewed·2022-05-14
CVE-2017-17439 [HIGH] CWE-476 GHSA-gc5p-r2vh-qc88: In Heimdal through 7
In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet containing empty data fields for client name or realm. The parser would unconditionally dereference NULL pointers in that case, leading to a segmentation fault. This is related to the _kdc_as_rep function in kdc/kerberos5.c and the der_length_visible_string function in lib/asn1/der_length.c.
OSV
CVE-2017-17439: In Heimdal through 7
osv·2017-12-06·CVSS 7.5
CVE-2017-17439 [HIGH] CVE-2017-17439: In Heimdal through 7
In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet containing empty data fields for client name or realm. The parser would unconditionally dereference NULL pointers in that case, leading to a segmentation fault. This is related to the _kdc_as_rep function in kdc/kerberos5.c and the der_length_visible_string function in lib/asn1/der_length.c.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-17439 heimdal: NULL pointer dereference via crafted UDP packets [epel-all]
bugzilla·2017-12-11·CVSS 7.5
CVE-2017-17439 [HIGH] CVE-2017-17439 heimdal: NULL pointer dereference via crafted UDP packets [epel-all]
CVE-2017-17439 heimdal: NULL pointer dereference via crafted UDP packets [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
Bugzilla
CVE-2017-17439 heimdal: NULL pointer dereference via crafted UDP packets
bugzilla·2017-12-11·CVSS 7.5
CVE-2017-17439 [HIGH] CVE-2017-17439 heimdal: NULL pointer dereference via crafted UDP packets
CVE-2017-17439 heimdal: NULL pointer dereference via crafted UDP packets
In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet containing empty data fields for client name or realm. The parser would unconditionally dereference NULL pointers in that case, leading to a segmentation fault. This is related to the _kdc_as_rep function in kdc/kerberos5.c and the der_length_visible_string function in lib/asn1/der_length.c.
Upstream issue:
https://github.com/heimdal/heimdal/issues/353
Upstream patch:
https://github.com/heimdal/heimdal/commit/1a6a6e462dc2ac6111f9e02c6852ddec4849b887
References:
http://www.h5l.org/pipermail/heimdal-discuss/2017-August/000259.html
Discussion:
Created heimdal tracking bugs for this issue:
Affects:
Bugzilla
CVE-2017-17439 heimdal: NULL pointer dereference via crafted UDP packets [fedora-all]
bugzilla·2017-12-11·CVSS 7.5
CVE-2017-17439 [HIGH] CVE-2017-17439 heimdal: NULL pointer dereference via crafted UDP packets [fedora-all]
CVE-2017-17439 heimdal: NULL pointer dereference via crafted UDP packets [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
http://h5l.org/advisories.html?show=2017-12-08http://www.h5l.org/pipermail/heimdal-announce/2017-December/000008.htmlhttp://www.h5l.org/pipermail/heimdal-discuss/2017-August/000259.htmlhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=878144https://github.com/heimdal/heimdal/commit/1a6a6e462dc2ac6111f9e02c6852ddec4849b887https://github.com/heimdal/heimdal/issues/353https://www.debian.org/security/2017/dsa-4055http://h5l.org/advisories.html?show=2017-12-08http://www.h5l.org/pipermail/heimdal-announce/2017-December/000008.htmlhttp://www.h5l.org/pipermail/heimdal-discuss/2017-August/000259.htmlhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=878144https://github.com/heimdal/heimdal/commit/1a6a6e462dc2ac6111f9e02c6852ddec4849b887https://github.com/heimdal/heimdal/issues/353https://www.debian.org/security/2017/dsa-4055
2017-12-06
Published