Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Multiple vulnerabilities have been discovered in Heimdal, the worst of which could lead to remote code execution on a KDC.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202310-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Heimdal: Multiple Vulnerabilities Date: October 08, 2023 Bugs: #881429, #893722 ID: 202310-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in Heimdal, the worst of which could lead to remote code execution on a KDC. Background ========== Heimdal is a free implementation of Kerberos 5. Affected packages ================= Package Vulnerable Unaffected ----------------- ------------ ------------ app-crypt/heimdal < 7.8.0-r1 > = 7.8.0-r1 Description =========== Multiple vulnerabilities have been discovered in Heimdal, the worst of which could lead to remote code execution on a Kerberos Domain Controller. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All Cross-realm trust vulnerability in Heimdal users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-crypt/heimdal-7.8.0-r1" References ========== [ 1 ] CVE-2019-14870 https://nvd.nist.gov/vuln/detail/CVE-2019-14870 [ 2 ] CVE-2021-44758 https://nvd.nist.gov/vuln/detail/CVE-2021-44758 [ 3 ] CVE-2022-3437 https://nvd.nist.gov/vuln/detail/CVE-2022-3437 [ 4 ] CVE-2022-3671 https://nvd.nist.gov/vuln/detail/CVE-2022-3671 [ 5 ] CVE-2022-41916 https://nvd.nist.gov/vuln/detail/CVE-2022-41916 [ 6 ] CVE-2022-42898 https://nvd.nist.gov/vuln/detail/CVE-2022-42898 [ 7 ] CVE-2022-44640 https://nvd.nist.gov/vuln/detail/CVE-2022-44640 [ 8 ] CVE-2022-44758 https://nvd.nist.gov/vuln/detail/CVE-2022-44758 [ 9 ] CVE-2022-45142 https://nvd.nist.gov/vuln/detail/CVE-2022-45142 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202310-06 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Helmut Grohne discovered a flaw in Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos. The backports of fixes for CVE-2022-3437 accidentally inverted important memory comparisons in the arcfour-hmac-md5 and rc4-hmac integrity check . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5344-1
I discovered a flaw in Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos. The backports of fixes for CVE-2022-3437 accidentally inverted important memory comparisons in the arcfour-hmac-md5 and rc4-hmac integrity check handlers for gssapi, . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3311-1
Heimdal could be made to crash if it received specially crafted network traffic.. =========================================================================Ubuntu Security Notice USN-5766-1 December 07, 2022 heimdal vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 ESM - Ubuntu 14.04 ESM Summary: Heimdal could be made to crash if it received specially crafted network traffic. Software Description: - heimdal: Heimdal Kerberos Network Authentication Protocol Details: It was discovered that Heimdal did not properly manage memory when normalizing Unicode. An attacker could possibly use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: libwind0-heimdal 7.7.0+dfsg-1ubuntu1.2 Ubuntu 18.04 LTS: libwind0-heimdal 7.5.0+dfsg-1ubuntu0.2 Ubuntu 16.04 ESM: libwind0-heimdal 1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm2 Ubuntu 14.04 ESM: libwind0-heimdal 1.6~git20131207+dfsg-1ubuntu1.2+esm2 After a standard system update you need to restart any application using Heimdal libraries to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5766-1 CVE-2022-41916 Package Information: https://launchpad.net/ubuntu/+source/heimdal/7.7.0+dfsg-1ubuntu1.2 https://launchpad.net/ubuntu/+source/heimdal/7.5.0+dfsg-1ubuntu0.2 . The Heimdal flaw impacts various Debian releases. Ensure updates are applied quickly to avoid system failures triggered by specific network requests.. Heimdal Vulnerability, Ubuntu Security, Service Crash Risk. . Severity: Important. LinuxSecurity.com Team
Multiple security vulnerabilities were discovered in heimdal, an implementation of the Kerberos 5 authentication protocol, which may result in denial of service, information disclosure, or remote code execution. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3206-1
Several vulnerabilities were discovered in Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos. CVE-2021-3671 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5287-1
Heimdal was not properly handling logical conditions that related to memory management operations. An attacker could possibly use this issue to cause a denial of service. (CVE-2022-3116) References: . MGASA-2022-0395 - Updated heimdal packages fix security vulnerability Publication date: 28 Oct 2022 URL: https://advisories.mageia.org/MGASA-2022-0395.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-3116 Heimdal was not properly handling logical conditions that related to memory management operations. An attacker could possibly use this issue to cause a denial of service. (CVE-2022-3116) References: - https://bugs.mageia.org/show_bug.cgi?id=30962 - https://ubuntu.com/security/notices/USN-5675-1 - https://www.cve.org/CVERecord?id=CVE-2022-3116 SRPMS: - 8/core/heimdal-7.7.0-5.2.mga8 . The recent Heimdal security patch resolves a service disruption vulnerability in Mageia versions, enhancing memory handling protocols.. Heimdal Security, Mageia Updates, Memory Management Fix. . LinuxSecurity.com Team
A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash a samba server using heimdal . MGASA-2021-0543 - Updated heimdal packages fix security vulnerability Publication date: 08 Dec 2021 URL: https://advisories.mageia.org/MGASA-2021-0543.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-3671 A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash a samba server using heimdal References: - https://bugs.mageia.org/show_bug.cgi?id=29658 - https://ubuntu.com/security/CVE-2021-3671 - https://www.cve.org/CVERecord?id=CVE-2021-3671 SRPMS: - 8/core/heimdal-7.7.0-5.1.mga8 . Heimdal updates released to patch vulnerability in samba kerberos service. Significant risks mitigated. Discover further information.. Samba Kerberos, Heimdal Security, Mageia Update, Null Pointer Issue. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.