Debian Heimdal vulnerabilities
25 known vulnerabilities affecting debian/heimdal.
Total CVEs
25
CISA KEV
0
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH12MEDIUM7LOW1
Vulnerabilities
Page 2 of 2
CVE-2006-0677P4HIGHCVSS 7.8fixed in heimdal 0.7.2-1 (bookworm)2006
CVE-2006-0677 [HIGH] CVE-2006-0677: heimdal - telnetd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2 allows remote unaut...
telnetd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2 allows remote unauthenticated attackers to cause a denial of service (server crash) via unknown vectors that trigger a null dereference.
Scope: local
bookworm: resolved (fixed in 0.7.2-1)
bullseye: resolved (fixed in 0.7.2-1)
forky: resolved (fixed in 0.7.2-1)
sid: resolved (fixed in 0.7.2-1)
trixie: resolve
debian
CVE-2003-0138P4HIGHCVSS 7.5fixed in heimdal 0.5.2-1 (bookworm)2003
CVE-2003-0138 [HIGH] CVE-2003-0138: heimdal - Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages...
Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.
Scope: local
bookworm: resolved (fixed in 0.5.2-1)
bullseye: resolved (fixed in 0.5.2-1)
forky: resolved (fixed in 0.5.2-1)
sid: resolved (fixed in 0.5.2-1)
trixie: resolved (fixed in 0.5.2-1)
debian
CVE-2005-2040P4HIGHCVSS 7.5fixed in heimdal 0.6.3-11 (bookworm)2005
CVE-2005-2040 [HIGH] CVE-2005-2040: heimdal - Multiple buffer overflows in the getterminaltype function in telnetd for Heimdal...
Multiple buffer overflows in the getterminaltype function in telnetd for Heimdal before 0.6.5 may allow remote attackers to execute arbitrary code, a different vulnerability than CVE-2005-0468 and CVE-2005-0469.
Scope: local
bookworm: resolved (fixed in 0.6.3-11)
bullseye: resolved (fixed in 0.6.3-11)
forky: resolved (fixed in 0.6.3-11)
sid: resolved (fixed in 0.6.3-1
debian
CVE-2004-0371P4MEDIUMCVSS 5.0fixed in heimdal 0.6.1-1 (bookworm)2004
CVE-2004-0371 [MEDIUM] CVE-2004-0371: heimdal - Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not properly perform cert...
Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not properly perform certain consistency checks for cross-realm requests, which allows remote attackers with control of a realm to impersonate others in the cross-realm trust path.
Scope: local
bookworm: resolved (fixed in 0.6.1-1)
bullseye: resolved (fixed in 0.6.1-1)
forky: resolved (fixed in 0.6.1-1)
sid: res
debian
CVE-2006-0582P4LOWCVSS 2.1fixed in heimdal 0.7.2-1 (bookworm)2006
CVE-2006-0582 [LOW] CVE-2006-0582: heimdal - Unspecified vulnerability in rshd in Heimdal 0.6.x before 0.6.6 and 0.7.x before...
Unspecified vulnerability in rshd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2, when storing forwarded credentials, allows attackers to overwrite arbitrary files and change file ownership via unknown vectors.
Scope: local
bookworm: resolved (fixed in 0.7.2-1)
bullseye: resolved (fixed in 0.7.2-1)
forky: resolved (fixed in 0.7.2-1)
sid: resolved (fixed in 0.7.2-
debian
← Previous2 / 2