Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 506
Alerts This Week
Warning Icon 1 506

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 20 articles for you...
91

Gentoo: GLSA-202310-06 High: Heimdal Remote Code Execution Risks

Multiple vulnerabilities have been discovered in Heimdal, the worst of which could lead to remote code execution on a KDC.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202310-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Heimdal: Multiple Vulnerabilities Date: October 08, 2023 Bugs: #881429, #893722 ID: 202310-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in Heimdal, the worst of which could lead to remote code execution on a KDC. Background ========== Heimdal is a free implementation of Kerberos 5. Affected packages ================= Package Vulnerable Unaffected ----------------- ------------ ------------ app-crypt/heimdal < 7.8.0-r1 > = 7.8.0-r1 Description =========== Multiple vulnerabilities have been discovered in Heimdal, the worst of which could lead to remote code execution on a Kerberos Domain Controller. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All Cross-realm trust vulnerability in Heimdal users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-crypt/heimdal-7.8.0-r1" References ========== [ 1 ] CVE-2019-14870 https://nvd.nist.gov/vuln/detail/CVE-2019-14870 [ 2 ] CVE-2021-44758 https://nvd.nist.gov/vuln/detail/CVE-2021-44758 [ 3 ] CVE-2022-3437 https://nvd.nist.gov/vuln/detail/CVE-2022-3437 [ 4 ] CVE-2022-3671 https://nvd.nist.gov/vuln/detail/CVE-2022-3671 [ 5 ] CVE-2022-41916 https://nvd.nist.gov/vuln/detail/CVE-2022-41916 [ 6 ] CVE-2022-42898 https://nvd.nist.gov/vuln/detail/CVE-2022-42898 [ 7 ] CVE-2022-44640 https://nvd.nist.gov/vuln/detail/CVE-2022-44640 [ 8 ] CVE-2022-44758 https://nvd.nist.gov/vuln/detail/CVE-2022-44758 [ 9 ] CVE-2022-45142 https://nvd.nist.gov/vuln/detail/CVE-2022-45142 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202310-06 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2023 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo Security Advisory 202310-07 highlights severe vulnerabilities within the OpenSSL library that may allow attackers to execute remote code on affected systems.. Gentoo Advisory, Heimdal Threat, Code Execution Risk. . LinuxSecurity.com Team

Calendar%202 Oct 08, 2023 Gentoo
87

Debian: DSA-5344-1 Critical: Heimdal Memory Flaw and Update

Helmut Grohne discovered a flaw in Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos. The backports of fixes for CVE-2022-3437 accidentally inverted important memory comparisons in the arcfour-hmac-md5 and rc4-hmac integrity check . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5344-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso February 08, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : heimdal CVE ID : CVE-2022-45142 Debian Bug : 1030849 Helmut Grohne discovered a flaw in Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos. The backports of fixes for CVE-2022-3437 accidentally inverted important memory comparisons in the arcfour-hmac-md5 and rc4-hmac integrity check handlers for gssapi, resulting in incorrect validation of message integrity codes. For the stable distribution (bullseye), this problem has been fixed in version 7.7.0+dfsg-2+deb11u3. We recommend that you upgrade your heimdal packages. For the detailed security status of heimdal please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/heimdal Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu Security Notice USN-4185-1 for OpenSSL fixes severe buffer overflow vulnerabilities.. Heimdal Memory Flaw, Debian Security Advisory, Critical Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 08, 2023 Critical Debian
197

Debian 10 Buster DLA-3311-1 Critical Heimdal Integrity Issue

I discovered a flaw in Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos. The backports of fixes for CVE-2022-3437 accidentally inverted important memory comparisons in the arcfour-hmac-md5 and rc4-hmac integrity check handlers for gssapi, . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3311-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Helmut Grohne February 08, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : heimdal Version : 7.5.0+dfsg-3+deb10u2 CVE ID : CVE-2022-45142 Debian Bug : #1030849 I discovered a flaw in Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos. The backports of fixes for CVE-2022-3437 accidentally inverted important memory comparisons in the arcfour-hmac-md5 and rc4-hmac integrity check handlers for gssapi, resulting in incorrect validation of message integrity codes. For Debian 10 buster, this problem has been fixed in version 7.5.0+dfsg-3+deb10u2. We recommend that you upgrade your heimdal packages. For the detailed security status of heimdal please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/heimdal Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-3312-1 regarding openssl resolves buffer overflow vulnerabilities affecting ssl connection security.. Heimdal Security, Debian Advisory, Kerberos Compatibility. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 08, 2023 Critical Debian LTS
172

Ubuntu 20.04 USN-5766-1: heimdal Denial Of Service Threat

Heimdal could be made to crash if it received specially crafted network traffic.. =========================================================================Ubuntu Security Notice USN-5766-1 December 07, 2022 heimdal vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 ESM - Ubuntu 14.04 ESM Summary: Heimdal could be made to crash if it received specially crafted network traffic. Software Description: - heimdal: Heimdal Kerberos Network Authentication Protocol Details: It was discovered that Heimdal did not properly manage memory when normalizing Unicode. An attacker could possibly use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: libwind0-heimdal 7.7.0+dfsg-1ubuntu1.2 Ubuntu 18.04 LTS: libwind0-heimdal 7.5.0+dfsg-1ubuntu0.2 Ubuntu 16.04 ESM: libwind0-heimdal 1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm2 Ubuntu 14.04 ESM: libwind0-heimdal 1.6~git20131207+dfsg-1ubuntu1.2+esm2 After a standard system update you need to restart any application using Heimdal libraries to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5766-1 CVE-2022-41916 Package Information: https://launchpad.net/ubuntu/+source/heimdal/7.7.0+dfsg-1ubuntu1.2 https://launchpad.net/ubuntu/+source/heimdal/7.5.0+dfsg-1ubuntu0.2 . The Heimdal flaw impacts various Debian releases. Ensure updates are applied quickly to avoid system failures triggered by specific network requests.. Heimdal Vulnerability, Ubuntu Security, Service Crash Risk. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 07, 2022 Important Ubuntu
197

Debian 10: DLA-3206-1 Critical: Resolved Heimdal Vulnerabilities

Multiple security vulnerabilities were discovered in heimdal, an implementation of the Kerberos 5 authentication protocol, which may result in denial of service, information disclosure, or remote code execution. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3206-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin November 26, 2022 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : heimdal Version : 7.5.0+dfsg-3+deb10u1 CVE ID : CVE-2019-14870 CVE-2021-3671 CVE-2021-44758 CVE-2022-3437 CVE-2022-41916 CVE-2022-42898 CVE-2022-44640 Debian Bug : 946786 996586 1024187 Multiple security vulnerabilities were discovered in heimdal, an implementation of the Kerberos 5 authentication protocol, which may result in denial of service, information disclosure, or remote code execution. CVE-2019-14870 Isaac Boukris reported that the Heimdal KDC before 7.7.1 does not apply delegation_not_allowed (aka not-delegated) user attributes for S4U2Self. Instead the forwardable flag is set even if the impersonated client has the not-delegated flag set. CVE-2021-3671 Joseph Sutton discovered that the Heimdal KDC before 7.7.1 does not check for missing missing sname in TGS-REQ (Ticket Granting Server - Request) before before dereferencing. An authenticated user could use this flaw to crash the KDC. CVE-2021-44758 It was discovered that Heimdal is prone to a NULL dereference in acceptors when the initial SPNEGO token has no acceptable mechanisms, which may result in denial of service for a server application that uses the Simple and Protected GSSAPI Negotiation Mechanism (SPNEGO). CVE-2022-3437 Evgeny Legerov reported that the DES and Triple-DES decryption routines in the Heimdal GSSAPI library before 7.7.1 were proneto buffer overflow on malloc() allocated memory when presented with a maliciously small packet. In addition, the Triple-DES and RC4 (arcfour) decryption routine were prone to non-constant time leaks, which could potentially yield to a leak of secret key material when using these ciphers. CVE-2022-41916 It was discovered that Heimdal's PKI certificate validation library before 7.7.1 can under some circumstances perform an out-of-bounds memory access when normalizing Unicode, which may result in denial of service. CVE-2022-42898 Greg Hudson discovered an integer multiplication overflow in the Privilege Attribute Certificate (PAC) parsing routine, which may result in denial of service for Heimdal KDCs and possibly Heimdal servers (e.g., via GSS-API) on 32-bit systems. CVE-2022-44640 Douglas Bagnall and the Heimdal maintainers independently discovered that Heimdal's ASN.1 compiler before 7.7.1 generates code that allows specially crafted DER encodings of CHOICEs to invoke the wrong free() function on the decoded structure upon decode error, which may result in remote code execution in the Heimdal KDC and possibly the Kerberos client, the X.509 library, and other components as well. For Debian 10 buster, these problems have been fixed in version 7.5.0+dfsg-3+deb10u1. We recommend that you upgrade your heimdal packages. For the detailed security status of heimdal please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/heimdal Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Several security flaws in the Heimdal authentication framework have been addressed in Debian LTS DLA-3206-1. Ensure you update your packages promptly.. Heimdal Security Update, Debian Advisory, Kerberos Exploit Risks. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 26, 2022 Critical Debian LTS
87

Debian: DSA-5287-1 Urgent Heimdal Denial Of Service Vulnerability

Several vulnerabilities were discovered in Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos. CVE-2021-3671 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5287-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso November 22, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : heimdal CVE ID : CVE-2021-3671 CVE-2021-44758 CVE-2022-3437 CVE-2022-41916 CVE-2022-42898 CVE-2022-44640 Debian Bug : 996586 Several vulnerabilities were discovered in Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos. CVE-2021-3671 Joseph Sutton discovered that the Heimdal KDC does not validate that the server name in the TGS-REQ is present before dereferencing, which may result in denial of service. CVE-2021-44758 It was discovered that Heimdal is prone to a NULL dereference in acceptors where an initial SPNEGO token that has no acceptable mechanisms, which may result in denial of service for a server application that uses SPNEGO. CVE-2022-3437 Several buffer overflow flaws and non-constant time leaks were discovered when using 1DES, 3DES or RC4 (arcfour). CVE-2022-41916 An out-of-bounds memory access was discovered when Heimdal normalizes Unicode, which may result in denial of service. CVE-2022-42898 It was discovered that integer overflows in PAC parsing may result in denial of service for Heimdal KDCs or possibly Heimdal servers. CVE-2022-44640 It was discovered that the Heimdal's ASN.1 compiler generates code that allows specially crafted DER encodings to invoke an invalid free on the decoded structure upon decode error, which may result in remote code execution in the Heimdal KDC. For the stable distribution (bullseye), theseproblems have been fixed in version 7.7.0+dfsg-2+deb11u2. We recommend that you upgrade your heimdal packages. For the detailed security status of heimdal please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/heimdal Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu Security Notice USN-5112-1 announces essential updates for OpenSSL to mitigate significant vulnerabilities and risks.. Debian Heimdal Update, Kerberos Security, Denial of Service Threat. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 22, 2022 Critical Debian
203

Mageia 8: MGASA-2022-0395 Moderate: Heimdal Denial Of Service

Heimdal was not properly handling logical conditions that related to memory management operations. An attacker could possibly use this issue to cause a denial of service. (CVE-2022-3116) References: . MGASA-2022-0395 - Updated heimdal packages fix security vulnerability Publication date: 28 Oct 2022 URL: https://advisories.mageia.org/MGASA-2022-0395.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-3116 Heimdal was not properly handling logical conditions that related to memory management operations. An attacker could possibly use this issue to cause a denial of service. (CVE-2022-3116) References: - https://bugs.mageia.org/show_bug.cgi?id=30962 - https://ubuntu.com/security/notices/USN-5675-1 - https://www.cve.org/CVERecord?id=CVE-2022-3116 SRPMS: - 8/core/heimdal-7.7.0-5.2.mga8 . The recent Heimdal security patch resolves a service disruption vulnerability in Mageia versions, enhancing memory handling protocols.. Heimdal Security, Mageia Updates, Memory Management Fix. . LinuxSecurity.com Team

Calendar%202 Oct 28, 2022 Mageia
203

Mageia 8: MGASA-2021-0543 Critical: Heimdal Samba Null Pointer Error

A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash a samba server using heimdal . MGASA-2021-0543 - Updated heimdal packages fix security vulnerability Publication date: 08 Dec 2021 URL: https://advisories.mageia.org/MGASA-2021-0543.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-3671 A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash a samba server using heimdal References: - https://bugs.mageia.org/show_bug.cgi?id=29658 - https://ubuntu.com/security/CVE-2021-3671 - https://www.cve.org/CVERecord?id=CVE-2021-3671 SRPMS: - 8/core/heimdal-7.7.0-5.1.mga8 . Heimdal updates released to patch vulnerability in samba kerberos service. Significant risks mitigated. Discover further information.. Samba Kerberos, Heimdal Security, Mageia Update, Null Pointer Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 08, 2021 Critical Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200