cbcvebase.
CVE-2022-44640
published 2022-12-25

CVE-2022-44640: Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Center (KDC).

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Center (KDC).

Affected

23 ranges
VendorProductVersion rangeFixed in
debianheimdal< heimdal 7.8.git20221115.a6cf945+dfsg-1 (bookworm)heimdal 7.8.git20221115.a6cf945+dfsg-1 (bookworm)
debiansamba< heimdal 7.8.git20221115.a6cf945+dfsg-1 (bookworm)heimdal 7.8.git20221115.a6cf945+dfsg-1 (bookworm)
heimdal_projectheimdal< 7.7.17.7.1
heimdal_projectheimdal>= 0 < 7.7.0+dfsg-2+deb11u27.7.0+dfsg-2+deb11u2
heimdal_projectheimdal>= 0 < 7.8.git20221115.a6cf945+dfsg-17.8.git20221115.a6cf945+dfsg-1
heimdal_projectheimdal>= 0 < 7.8.git20221115.a6cf945+dfsg-17.8.git20221115.a6cf945+dfsg-1
heimdal_projectheimdal>= 0 < 7.8.git20221115.a6cf945+dfsg-17.8.git20221115.a6cf945+dfsg-1
heimdal_projectheimdal>= 0 < 7.5.0+dfsg-1ubuntu0.37.5.0+dfsg-1ubuntu0.3
heimdal_projectheimdal>= 0 < 7.7.0+dfsg-1ubuntu1.37.7.0+dfsg-1ubuntu1.3
heimdal_projectheimdal>= 0 < 1.6~git20131207+dfsg-1ubuntu1.2+esm31.6~git20131207+dfsg-1ubuntu1.2+esm3
heimdal_projectheimdal>= 0 < 1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm31.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3
msrcazl3_samba_4.18.3-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_heimdal_7.7.1-1_on_cbl_mariner_1.0
sambasamba>= 0 < 2:4.17.4+dfsg-12:4.17.4+dfsg-1
sambasamba>= 0 < 2:4.17.4+dfsg-12:4.17.4+dfsg-1
sambasamba>= 0 < 2:4.17.4+dfsg-12:4.17.4+dfsg-1
sambasamba>= 4.15.0 < 4.15.34.15.3
sambasamba>= 4.16.0 < 4.16.84.16.8
sambasamba>= 4.17.0 < 4.17.44.17.4

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL