The Heimdal Software Kerberos 5 implementation is vulnerable to a null pointer dereferance. An attacker with network access to an application that depends on the vulnerable code path can cause the application to crash.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ubuntu | — | Upgrade heimdal-kdc (Ubuntu Pro)Upgrade heimdal-clients (Ubuntu Pro)Upgrade libgssapi3-heimdal (Ubuntu Pro)Upgrade heimdal-kdcUpgrade libkdc2-heimdalUpgrade heimdal-clientsUpgrade heimdal-servers (Ubuntu Pro)Upgrade libkrb5-26-heimdal (Ubuntu Pro)Upgrade libkdc2-heimdal (Ubuntu Pro)Upgrade heimdal-kcm (Ubuntu Pro)Upgrade heimdal-kcmUpgrade heimdal-clients-x (Ubuntu Pro)Upgrade libkrb5-26-heimdalUpgrade heimdal-serversUpgrade libgssapi3-heimdalUpgrade heimdal-servers-x (Ubuntu Pro) | Oct 14, 2022 | Oct 13, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub