cbcvebase.

Debian Heimdal vulnerabilities

25 known vulnerabilities affecting debian/heimdal.

Total CVEs
25
CISA KEV
0
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH12MEDIUM7LOW1

Vulnerabilities

Page 1 of 2
CVE-2011-4862P1HIGHCVSS 10.0ExploitedPoCfixed in heimdal 1.5.dfsg.1-1 (bookworm)2011
CVE-2011-4862 [CRITICAL] CVE-2011-4862: heimdal - Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MI... Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011. Scope: local bookworm: reso
debian
CVE-2002-1235P2CRITICALCVSS 10.0Exploitedfixed in heimdal 0.4e-22 (bookworm)2002
CVE-2002-1235 [CRITICAL] CVE-2002-1235: heimdal - The kadm_ser_in function in (1) the Kerberos v4compatibility administration daem... The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before 0.5.1 when compiled with Kerberos 4 support, does not properly verify the length field of a request, which allows r
debian
CVE-2022-44640P3CRITICALCVSS 9.8fixed in heimdal 7.8.git20221115.a6cf945+dfsg-1 (bookworm)2022
CVE-2022-44640 [CRITICAL] CVE-2022-44640: heimdal - Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because o... Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Center (KDC). Scope: local bookworm: resolved (fixed in 7.8.git20221115.a6cf945+dfsg-1) bullseye: resolved (fixed in 7.7.0+dfsg-2+deb11u2) forky: resolved (fixed in 7.8.git20221115.a6cf945+dfsg-1) sid: resolved (fixed
debian
CVE-2022-42898P3HIGHCVSS 8.8fixed in heimdal 7.8.git20221115.a6cf945+dfsg-1 (bookworm)2022
CVE-2022-42898 [HIGH] CVE-2022-42898: heimdal - PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 ... PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb
debian
CVE-2017-11103P3HIGHCVSS 8.1fixed in heimdal 7.4.0.dfsg.1-1 (bookworm)2017
CVE-2017-11103 [HIGH] CVE-2017-11103: heimdal - Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus'... Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'
debian
CVE-2018-16860P3HIGHCVSS 7.5fixed in heimdal 7.5.0+dfsg-3 (bookworm)2018
CVE-2018-16860 [HIGH] CVE-2018-16860: heimdal - A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, ex... A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that
debian
CVE-2017-17439P3HIGHCVSS 7.5fixed in heimdal 7.5.0+dfsg-1 (bookworm)2017
CVE-2017-17439 [HIGH] CVE-2017-17439: heimdal - In Heimdal through 7.4, remote unauthenticated attackers are able to crash the K... In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet containing empty data fields for client name or realm. The parser would unconditionally dereference NULL pointers in that case, leading to a segmentation fault. This is related to the _kdc_as_rep function in kdc/kerberos5.c and the der_length_visible_st
debian
CVE-2017-6594P3HIGHCVSS 7.5fixed in heimdal 7.1.0+dfsg-12 (bookworm)2017
CVE-2017-6594 [HIGH] CVE-2017-6594: heimdal - The transit path validation code in Heimdal before 7.3 might allow attackers to ... The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath policy protection mechanism by leveraging failure to add the previous hop realm to the transit path of issued tickets. Scope: local bookworm: resolved (fixed in 7.1.0+dfsg-12) bullseye: resolved (fixed in 7.1.0+dfsg-12) forky: resolved (fixed in 7.1.0+dfsg-12) sid: resolv
debian
CVE-2005-0469P3HIGHCVSS 7.5fixed in heimdal 0.6.3-10 (bookworm)2005
CVE-2005-0469 [HIGH] CVE-2005-0469: heimdal - Buffer overflow in the slc_add_reply function in various BSD-based Telnet client... Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands. Scope: local bookworm: resolved (fixed in 0.6.3-10) bullseye: resolved (fixed in 0.6.3-10) forky: resolved (fixed in 0.6.3-10) sid:
debian
CVE-2022-41916P3MEDIUMCVSS 5.9fixed in heimdal 7.8.git20221115.a6cf945+dfsg-1 (bookworm)2022
CVE-2022-41916 [MEDIUM] CVE-2022-41916: heimdal - Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to... Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of service vulnerability in Heimdal's PKI certificate validation library, affecting the KDC (via PKINIT) and kinit (via PKINIT), as well as any third-party applications using Heimdal's libhx509. Users should upgrade to Heimdal 7.7.1 or 7.8. There are n
debian
CVE-2019-12098P3HIGHCVSS 7.4fixed in heimdal 7.5.0+dfsg-3 (bookworm)2019
CVE-2019-12098 [HIGH] CVE-2019-12098: heimdal - In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT P... In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c. Scope: local bookworm: resolved (fixed in 7.5.0+dfsg-3) bullseye: resolved (fixed in 7.5.0+dfsg-3) forky: resolved (fixed in 7.5.0+dfsg-3) sid: resolved (fixed
debian
CVE-2022-3437P3MEDIUMCVSS 6.5fixed in heimdal 7.8.git20221115.a6cf945+dfsg-1 (bookworm)2022
CVE-2022-3437 [MEDIUM] CVE-2022-3437: heimdal - A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI ... A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send sp
debian
CVE-2004-0434P3CRITICALCVSS 9.8fixed in heimdal 0.6.2-1 (bookworm)2004
CVE-2004-0434 [CRITICAL] CVE-2004-0434: heimdal - k5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code... k5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code via a Kerberos 4 compatibility administration request whose framing length is less than 2, which leads to a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 0.6.2-1) bullseye: resolved (fixed in 0.6.2-1) forky: resolved (fixed in 0.6.2-1) sid: resolved (fixed in 0
debian
CVE-2002-1225P3CRITICALCVSS 10.0fixed in heimdal 0.4e-21 (bookworm)2002
CVE-2002-1225 [CRITICAL] CVE-2002-1225: heimdal - Multiple buffer overflows in Heimdal before 0.5, possibly in both the (1) kadmin... Multiple buffer overflows in Heimdal before 0.5, possibly in both the (1) kadmind and (2) kdc servers, may allow remote attackers to gain root access. Scope: local bookworm: resolved (fixed in 0.4e-21) bullseye: resolved (fixed in 0.4e-21) forky: resolved (fixed in 0.4e-21) sid: resolved (fixed in 0.4e-21) trixie: resolved (fixed in 0.4e-21)
debian
CVE-2022-45142P3MEDIUMCVSS 6.5fixed in heimdal 7.8.git20221117.28daf24+dfsg-1.1 (bookworm)2022
CVE-2022-45142 [MEDIUM] CVE-2022-45142: heimdal - The fix for CVE-2022-3437 included changing memcmp to be constant time and a wor... The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arc
debian
CVE-2021-44758P4HIGHCVSS 7.5fixed in heimdal 7.8.git20221115.a6cf945+dfsg-1 (bookworm)2021
CVE-2021-44758 [HIGH] CVE-2021-44758: heimdal - Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a S... Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_response value to send_accept. Scope: local bookworm: resolved (fixed in 7.8.git20221115.a6cf945+dfsg-1) bullseye: resolved (fixed in 7.7.0+dfsg-2+deb11u2) forky: resolved (fixed in 7.8.git20221115.a6cf945+dfs
debian
CVE-2021-3671P3MEDIUMCVSS 6.5fixed in heimdal 7.7.0+dfsg-3 (bookworm)2021
CVE-2021-3671 [MEDIUM] CVE-2021-3671: heimdal - A null pointer de-reference was found in the way samba kerberos server handled m... A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server. Scope: local bookworm: resolved (fixed in 7.7.0+dfsg-3) bullseye: resolved (fixed in 7.7.0+dfsg-2+deb11u2) forky: resolved (fixed in 7.7.0+dfsg-3) sid: resolve
debian
CVE-2019-14870P3MEDIUMCVSS 5.4fixed in heimdal 7.7.0+dfsg-1 (bookworm)2019
CVE-2019-14870 [MEDIUM] CVE-2019-14870: heimdal - All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before ... All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwar
debian
CVE-2010-1321P4MEDIUMCVSS 6.8fixed in heimdal 1.4.0~git20100605.dfsg.1-1 (bookworm)2010
CVE-2010-1321 [MEDIUM] CVE-2010-1321: heimdal - The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library ... The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ m
debian
CVE-2002-1226P4CRITICALCVSS 10.0fixed in heimdal 0.4e-21 (bookworm)2002
CVE-2002-1226 [CRITICAL] CVE-2002-1226: heimdal - Unknown vulnerabilities in Heimdal before 0.5 with unknown impact, possibly in t... Unknown vulnerabilities in Heimdal before 0.5 with unknown impact, possibly in the (1) kadmind and (2) kdc servers, may allow remote or local attackers to gain root or other access, but not via buffer overflows (CVE-2002-1225). Scope: local bookworm: resolved (fixed in 0.4e-21) bullseye: resolved (fixed in 0.4e-21) forky: resolved (fixed in 0.4e-21) sid: resolved
debian
Debian Heimdal vulnerabilities | cvebase