PT-2017-14780 · Heimdal+1 · Heimdal+1

Michael Eder

+1

·

Publicado

2017-12-06

·

Atualizado

2018-08-16

·

CVE-2017-17439

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Heimdal versions prior to 7.5
Description The issue allows remote unauthenticated attackers to crash the KDC by sending a crafted UDP packet with empty data fields for client name or realm. This leads to a segmentation fault due to the parser unconditionally dereferencing NULL pointers. The problem is related to the kdc as rep function in kdc/kerberos5.c and the der length visible string function in lib/asn1/der length.c.
Recommendations For Heimdal versions prior to 7.5, update to version 7.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the KDC to minimize the risk of exploitation.

Correção

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-17439
DSA-4055-1
MGASA-2017-0485
OPENSUSE-SU-2018_2376-1
OPENSUSE-SU-2024:10946-1

Produtos afetados

Heimdal
Suse