CVE-2022-45142
published 2023-03-06CVE-2022-45142: The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.49%
39.0th percentile
The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | heimdal | < heimdal 7.8.git20221117.28daf24+dfsg-1.1 (bookworm) | heimdal 7.8.git20221117.28daf24+dfsg-1.1 (bookworm) |
| heimdal_project | heimdal | — | — |
| heimdal_project | heimdal | — | — |
| heimdal_project | heimdal | >= 0 < 7.7.0+dfsg-2+deb11u3 | 7.7.0+dfsg-2+deb11u3 |
| heimdal_project | heimdal | >= 0 < 7.8.git20221117.28daf24+dfsg-1.1 | 7.8.git20221117.28daf24+dfsg-1.1 |
| heimdal_project | heimdal | >= 0 < 7.8.git20221117.28daf24+dfsg-1.1 | 7.8.git20221117.28daf24+dfsg-1.1 |
| heimdal_project | heimdal | >= 0 < 7.8.git20221117.28daf24+dfsg-1.1 | 7.8.git20221117.28daf24+dfsg-1.1 |
| msrc | azl3_heimdal_7.8.0-3_on_azure_linux_3.0 | — | — |
| msrc | cbl2_heimdal_7.7.1-2_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_heimdal_7.7.1-2_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv6.5MEDIUM
vendor_msrc7.5HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Microsoft
The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to t
vendor_msrc·2023-03-14·CVSS 7.5
CVE-2022-45142 [MEDIUM] CWE-354 The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to t
The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transp
Red Hat
samba: fix introduced a logic inversion
vendor_redhat·2023-02-08·CVSS 6.5
CVE-2022-45142 [MEDIUM] CWE-354 samba: fix introduced a logic inversion
samba: fix introduced a logic inversion
The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.
Statement: Samba in RHEL is not compiled to use the Heimdal Kerberos library.
Versions of Samba shipped in Red Hat Enterprise Linux are compiled to use the system MIT Kerberos using the "--with-system-mitkrb5" argument, and these installations are not impacted, as the vulnerable code is not compiled into Samba.
Package: samba (Red Hat Enterprise Linux 6) - Not affecte
Ubuntu
Heimdal vulnerabilities
vendor_ubuntu·2023-02-08
CVE-2022-45142 Heimdal vulnerabilities
Title: Heimdal vulnerabilities
Summary: Heimdal could be made to crash if it received specially crafted
input.
Helmut Grohne discovered that Heimdal GSSAPI incorrectly handled logical
conditions that are related to memory management operations.
An attacker could possibly use this issue to cause a denial of service.
Instructions: After a standard system update you need to restart any application
using Heimdal libraries to make all the necessary changes.
Debian
CVE-2022-45142: heimdal - The fix for CVE-2022-3437 included changing memcmp to be constant time and a wor...
vendor_debian·2022·CVSS 6.5
CVE-2022-45142 [MEDIUM] CVE-2022-45142: heimdal - The fix for CVE-2022-3437 included changing memcmp to be constant time and a wor...
The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.
Scope: local
bookworm: resolved (fixed in 7.8.git20221117.28daf24+dfsg-1.1)
bullseye: resolved (fixed in 7.7.0+dfsg-2+deb11u3)
forky: resolved (fixed in 7.8.git20221117.28daf24+dfsg-1.1)
sid: resolved (fixed in 7.8.git20221117.28daf24+dfsg-1.1)
trixie: resolved (fixed in 7.8.git20221117.28daf24+dfsg-1.1)
GHSA
GHSA-5gp7-pf54-xc33: The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result
ghsa_unreviewed·2023-03-07·CVSS 6.5
CVE-2022-45142 [MEDIUM] CWE-354 GHSA-5gp7-pf54-xc33: The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result
The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.
OSV
CVE-2022-45142: The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result
osv·2023-03-06·CVSS 6.5
CVE-2022-45142 [MEDIUM] CVE-2022-45142: The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result
The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-06
Published