PT-2022-12224 · Heimdal+4 · Heimdal+4
Nicowilliams
·
Published
2022-11-22
·
Updated
2024-05-14
·
CVE-2021-44758
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Heimdal versions prior to 7.7.1
Description
The issue allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor. This can be achieved via a
preferred mech type of GSS C NO OID and a nonzero initial response value to send accept.Recommendations
For Heimdal versions prior to 7.7.1, update to version 7.7.1 or later to resolve the issue.
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Freebsd
Heimdal
Linuxmint
Ubuntu