The gss_userok function in appl/ftp/ftpd/gss_userok.c in Heimdal 0.7.2 does not allocate memory for the ticketfile pointer before calling free, which allows remote attackers to have an unknown impact via an invalid username. NOTE: the vulnerability was originally reported for ftpd.c, but this is incorrect.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade heimdal-lib-64bitUpgrade heimdal-devel-32bitUpgrade heimdal-lib-x86Upgrade heimdal-libUpgrade heimdal-develUpgrade heimdal-toolsUpgrade heimdalUpgrade heimdal-lib-32bitUpgrade heimdal-devel-64bit | Dec 12, 2013 | Dec 6, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub