Описание
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 7.5.0+dfsg-1ubuntu0.1 |
| cosmic | ignored | end of life |
| devel | not-affected | 7.5.0+dfsg-3build1 |
| disco | ignored | end of life |
| eoan | not-affected | 7.5.0+dfsg-3build1 |
| esm-apps/jammy | not-affected | 7.5.0+dfsg-3build1 |
| esm-infra-legacy/trusty | released | 1.6~git20131207+dfsg-1ubuntu1.2+esm1 |
| esm-infra/bionic | released | 7.5.0+dfsg-1ubuntu0.1 |
| esm-infra/focal | not-affected | 7.5.0+dfsg-3build1 |
| esm-infra/xenial | released | 1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1 |
Показывать по
EPSS
5.8 Medium
CVSS2
7.4 High
CVSS3
Связанные уязвимости
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
In the client side of Heimdal before 7.6.0, failure to verify anonymou ...
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
Уязвимость реализации Heimdal протокола Kerberos, связанная с ошибками управления криптографическими ключами, позволяющая нарушителю реализовать атаку типа «человек посередине»
EPSS
5.8 Medium
CVSS2
7.4 High
CVSS3