Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-11103

Опубликовано: 13 июл. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8
CVSS3: 8.1

Описание

Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.

РелизСтатусПримечание
devel

not-affected

7.4.0.dfsg.1-1
esm-infra-legacy/trusty

released

1.6~git20131207+dfsg-1ubuntu1.2
esm-infra/xenial

released

1.7~git20150920+dfsg-4ubuntu1.16.04.1
precise/esm

not-affected

1.6~git20120311.dfsg.1-2ubuntu0.2
trusty

released

1.6~git20131207+dfsg-1ubuntu1.2
trusty/esm

released

1.6~git20131207+dfsg-1ubuntu1.2
upstream

needs-triage

vivid/ubuntu-core

ignored

end of life
xenial

released

1.7~git20150920+dfsg-4ubuntu1.16.04.1
yakkety

released

1.7~git20150920+dfsg-4ubuntu1.16.10.1

Показывать по

РелизСтатусПримечание
devel

released

2:4.5.8+dfsg-2ubuntu4
esm-infra-legacy/trusty

released

2:4.3.11+dfsg-0ubuntu0.14.04.10
esm-infra/xenial

released

2:4.3.11+dfsg-0ubuntu0.16.04.9
precise/esm

not-affected

2:3.6.25-0ubuntu0.12.04.12
trusty

released

2:4.3.11+dfsg-0ubuntu0.14.04.10
trusty/esm

released

2:4.3.11+dfsg-0ubuntu0.14.04.10
upstream

needs-triage

vivid/ubuntu-core

DNE

xenial

released

2:4.3.11+dfsg-0ubuntu0.16.04.9
yakkety

released

2:4.4.5+dfsg-2ubuntu5.8

Показывать по

EPSS

Процентиль: 91%
0.06224
Низкий

6.8 Medium

CVSS2

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
redhat
больше 8 лет назад

Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.

CVSS3: 8.1
nvd
больше 8 лет назад

Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.

CVSS3: 8.1
debian
больше 8 лет назад

Heimdal before 7.4 allows remote attackers to impersonate services wit ...

suse-cvrf
больше 8 лет назад

Security update for samba and resource-agents

suse-cvrf
больше 8 лет назад

Security update for samba and resource-agents

EPSS

Процентиль: 91%
0.06224
Низкий

6.8 Medium

CVSS2

8.1 High

CVSS3