CVE-2019-12098
published 2019-05-15CVE-2019-12098: In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in…
PriorityP338high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
1.98%
78.3th percentile
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | heimdal | < heimdal 7.5.0+dfsg-3 (bookworm) | heimdal 7.5.0+dfsg-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| heimdal_project | heimdal | < 7.6.0 | 7.6.0 |
| heimdal_project | heimdal | >= 0 < 7.5.0+dfsg-3 | 7.5.0+dfsg-3 |
| heimdal_project | heimdal | >= 0 < 7.5.0+dfsg-3 | 7.5.0+dfsg-3 |
| heimdal_project | heimdal | >= 0 < 7.5.0+dfsg-3 | 7.5.0+dfsg-3 |
| heimdal_project | heimdal | >= 0 < 7.5.0+dfsg-3 | 7.5.0+dfsg-3 |
| heimdal_project | heimdal | >= 0 < 7.5.0+dfsg-1ubuntu0.1 | 7.5.0+dfsg-1ubuntu0.1 |
| heimdal_project | heimdal | >= 0 < 7.7.0+dfsg-1ubuntu1.1 | 7.7.0+dfsg-1ubuntu1.1 |
| heimdal_project | heimdal | >= 0 < 1.6~git20131207+dfsg-1ubuntu1.2+esm1 | 1.6~git20131207+dfsg-1ubuntu1.2+esm1 |
| heimdal_project | heimdal | >= 0 < 1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1 | 1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1 |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Heimdal 7.6.0 lib/krb5/init_creds_pw.c key management (ID 176913)
vuldb·2026-04-16·CVSS 7.4
CVE-2019-12098 [HIGH] Heimdal 7.6.0 lib/krb5/init_creds_pw.c key management (ID 176913)
A vulnerability was found in Heimdal 7.6.0. It has been declared as critical. Affected by this issue is some unknown functionality in the library lib/krb5/init_creds_pw.c. Such manipulation leads to key management error.
This vulnerability is uniquely identified as CVE-2019-12098. The attack can be launched remotely. No exploit exists.
OSV
heimdal vulnerabilities
osv·2022-10-13·CVSS 7.5
CVE-2018-16860 [HIGH] heimdal vulnerabilities
heimdal vulnerabilities
Isaac Boukris and Andrew Bartlett discovered that Heimdal's KDC was
not properly performing checksum algorithm verifications in the
S4U2Self extension module. An attacker could possibly use this issue
to perform a machine-in-the-middle attack and request S4U2Self
tickets for any user known by the application. This issue only
affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 LTS.
(CVE-2018-16860)
It was discovered that Heimdal was not properly handling the
verification of key exchanges when an anonymous PKINIT was being
used. An attacker could possibly use this issue to perform a
machine-in-the-middle attack and expose sensitive information.
This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and
Ubuntu 18.04 LTS. (CVE-2019-12098)
Joseph Sutton
GHSA
GHSA-pfc3-2w85-9453: In the client side of Heimdal before 7
ghsa_unreviewed·2022-05-24
CVE-2019-12098 [HIGH] GHSA-pfc3-2w85-9453: In the client side of Heimdal before 7
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
OSV
CVE-2019-12098: In the client side of Heimdal before 7
osv·2019-05-15·CVSS 7.4
CVE-2019-12098 [HIGH] CVE-2019-12098: In the client side of Heimdal before 7
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
Ubuntu
Heimdal vulnerabilities
vendor_ubuntu·2022-10-13·CVSS 7.5
CVE-2018-16860 [HIGH] Heimdal vulnerabilities
Title: Heimdal vulnerabilities
Summary: Several security issues were fixed in Heimdal.
Isaac Boukris and Andrew Bartlett discovered that Heimdal's KDC was
not properly performing checksum algorithm verifications in the
S4U2Self extension module. An attacker could possibly use this issue
to perform a machine-in-the-middle attack and request S4U2Self
tickets for any user known by the application. This issue only
affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 LTS.
(CVE-2018-16860)
It was discovered that Heimdal was not properly handling the
verification of key exchanges when an anonymous PKINIT was being
used. An attacker could possibly use this issue to perform a
machine-in-the-middle attack and expose sensitive information.
This issue only affected Ubuntu 14.04 ESM, Ubuntu
Debian
CVE-2019-12098: heimdal - In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT P...
vendor_debian·2019·CVSS 7.4
CVE-2019-12098 [HIGH] CVE-2019-12098: heimdal - In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT P...
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
Scope: local
bookworm: resolved (fixed in 7.5.0+dfsg-3)
bullseye: resolved (fixed in 7.5.0+dfsg-3)
forky: resolved (fixed in 7.5.0+dfsg-3)
sid: resolved (fixed in 7.5.0+dfsg-3)
trixie: resolved (fixed in 7.5.0+dfsg-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-12098 heimdall: heimdal: man-in-the-middle attack in function krb5_init_creds_step in lib/krb5/init_creds_pw.c [fedora-all]
bugzilla·2019-05-16·CVSS 7.4
CVE-2019-12098 [HIGH] CVE-2019-12098 heimdall: heimdal: man-in-the-middle attack in function krb5_init_creds_step in lib/krb5/init_creds_pw.c [fedora-all]
CVE-2019-12098 heimdall: heimdal: man-in-the-middle attack in function krb5_init_creds_step in lib/krb5/init_creds_pw.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message
Bugzilla
CVE-2019-12098 heimdal: man-in-the-middle attack in function krb5_init_creds_step in lib/krb5/init_creds_pw.c
bugzilla·2019-05-16·CVSS 7.4
CVE-2019-12098 [HIGH] CVE-2019-12098 heimdal: man-in-the-middle attack in function krb5_init_creds_step in lib/krb5/init_creds_pw.c
CVE-2019-12098 heimdal: man-in-the-middle attack in function krb5_init_creds_step in lib/krb5/init_creds_pw.c
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
Reference:
http://www.h5l.org/pipermail/heimdal-announce/2019-May/000009.html
Upstream commit:
https://github.com/heimdal/heimdal/commit/2f7f3d9960aa6ea21358bdf3687cee5149aa35cf
Discussion:
Created heimdal tracking bugs for this issue:
Affects: fedora-all [bug 1710841]
Created heimdall tracking bugs for this issue:
Affects: fedora-all [bug 1710842]
---
Created heimdal tracking bugs for this issue:
Affects: epel-all [bug 1710843]
---
This CVE Bugzilla entry is for
Bugzilla
CVE-2019-12098 heimdal: man-in-the-middle attack in function krb5_init_creds_step in lib/krb5/init_creds_pw.c [fedora-all]
bugzilla·2019-05-16·CVSS 7.4
CVE-2019-12098 [HIGH] CVE-2019-12098 heimdal: man-in-the-middle attack in function krb5_init_creds_step in lib/krb5/init_creds_pw.c [fedora-all]
CVE-2019-12098 heimdal: man-in-the-middle attack in function krb5_init_creds_step in lib/krb5/init_creds_pw.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: t
Bugzilla
CVE-2019-12098 heimdal: man-in-the-middle attack in function krb5_init_creds_step in lib/krb5/init_creds_pw.c [epel-all]
bugzilla·2019-05-16·CVSS 7.4
CVE-2019-12098 [HIGH] CVE-2019-12098 heimdal: man-in-the-middle attack in function krb5_init_creds_step in lib/krb5/init_creds_pw.c [epel-all]
CVE-2019-12098 heimdal: man-in-the-middle attack in function krb5_init_creds_step in lib/krb5/init_creds_pw.c [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-07/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00026.htmlhttp://www.h5l.org/pipermail/heimdal-announce/2019-May/000009.htmlhttps://github.com/heimdal/heimdal/commit/2f7f3d9960aa6ea21358bdf3687cee5149aa35cfhttps://github.com/heimdal/heimdal/compare/3e58559...bbafe72https://github.com/heimdal/heimdal/releases/tag/heimdal-7.6.0https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GIXEDVVMPD6ZAJSMI2EZ7FNEIVNWE5PD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SLXXIF4LOQEAEDAF4UGP2AO6WDNTDFUB/https://seclists.org/bugtraq/2019/Jun/1https://www.debian.org/security/2019/dsa-4455http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-07/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00026.htmlhttp://www.h5l.org/pipermail/heimdal-announce/2019-May/000009.htmlhttps://github.com/heimdal/heimdal/commit/2f7f3d9960aa6ea21358bdf3687cee5149aa35cfhttps://github.com/heimdal/heimdal/compare/3e58559...bbafe72https://github.com/heimdal/heimdal/releases/tag/heimdal-7.6.0https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GIXEDVVMPD6ZAJSMI2EZ7FNEIVNWE5PD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SLXXIF4LOQEAEDAF4UGP2AO6WDNTDFUB/https://seclists.org/bugtraq/2019/Jun/1https://www.debian.org/security/2019/dsa-4455
2019-05-15
Published