PT-2022-12224 · Heimdal+4 · Heimdal+4

Nicowilliams

·

Published

2022-11-22

·

Updated

2024-05-14

·

CVE-2021-44758

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Heimdal versions prior to 7.7.1
Description The issue allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor. This can be achieved via a preferred mech type of GSS C NO OID and a nonzero initial response value to send accept.
Recommendations For Heimdal versions prior to 7.7.1, update to version 7.7.1 or later to resolve the issue.

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

AZL-44859
CVE-2021-44758
DLA-3206-1
DSA-5287-1
GHSA-69H9-669W-88XV
MGASA-2022-0468
OPENSUSE-SU-2023:0019-1
OPENSUSE-SU-2023:0020-1
OPENSUSE-SU-2024:12580-1
ROSA-SA-2024-2419
USN-5800-1

Affected Products

Astra Linux
Freebsd
Heimdal
Linuxmint
Ubuntu