Логотип exploitDog
bind: "CVE-2022-45142"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2022-45142"

Количество 8

Количество 8

ubuntu логотип

CVE-2022-45142

больше 2 лет назад

The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-45142

больше 2 лет назад

The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.

EPSS: Низкий
nvd логотип

CVE-2022-45142

больше 2 лет назад

The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-45142

3 месяца назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-45142

больше 2 лет назад

The fix for CVE-2022-3437 included changing memcmp to be constant time ...

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20230417-02

около 2 лет назад

Уязвимость heimdal

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-5gp7-pf54-xc33

больше 2 лет назад

The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2023-02156

больше 2 лет назад

Уязвимость реализации протокола Kerberos5 heimdal, связанная с некорректным подтверждением значения проверки целостности, позволяющая нарушителю произвести логическую инверсию

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-45142

The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2022-45142

The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.

0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-45142

The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
msrc логотип
CVSS3: 7.5
0%
Низкий
3 месяца назад
debian логотип
CVE-2022-45142

The fix for CVE-2022-3437 included changing memcmp to be constant time ...

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
redos логотип
ROS-20230417-02

Уязвимость heimdal

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-5gp7-pf54-xc33

The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
fstec логотип
BDU:2023-02156

Уязвимость реализации протокола Kerberos5 heimdal, связанная с некорректным подтверждением значения проверки целостности, позволяющая нарушителю произвести логическую инверсию

CVSS3: 7.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу