The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade heimdal | Mar 26, 2024 | Mar 6, 2023 |
| Debian | — | Upgrade heimdal | Feb 10, 2023 | Feb 10, 2023 |
| Gentoo Linux | — | Upgrade app-crypt/heimdal. | Oct 10, 2023 | Mar 6, 2023 |
| Ubuntu | — | Upgrade libgssapi3-heimdal (Ubuntu Pro)Upgrade libgssapi3-heimdal | Mar 22, 2023 | Mar 6, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub