Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of service vulnerability in Heimdal's PKI certificate validation library, affecting the KDC (via PKINIT) and kinit (via PKINIT), as well as any third-party applications using Heimdal's libhx509. Users should upgrade to Heimdal 7.7.1 or 7.8. There are no known workarounds for this issue.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade heimdal | Mar 26, 2024 | Nov 15, 2022 |
| Debian | — | Upgrade heimdal | Nov 24, 2022 | Nov 15, 2022 |
| Gentoo Linux | — | Upgrade app-crypt/heimdal. | Oct 10, 2023 | Nov 15, 2022 |
| Suse | — | Upgrade libhcrypto4Upgrade libkrb5-26Upgrade libotp0Upgrade libsl0Upgrade libheimntlm0Upgrade libwind0Upgrade libheimbase1Upgrade libkafs0Upgrade libasn1-8Upgrade libheimedit0Upgrade libkadm5srv8Upgrade libheimdal-develUpgrade libhx509-5Upgrade libkdc2Upgrade libgssapi3Upgrade libhdb9Upgrade libroken18Upgrade libkadm5clnt7 | Jan 17, 2023 | Nov 15, 2022 |
| Ubuntu | — | Upgrade libwind0-heimdal (Ubuntu Pro)Upgrade libwind0-heimdal | Dec 8, 2022 | Nov 15, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub