CVE-2022-42898

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-42898
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-42898.json
Aliases
  • GHSA-64mq-fvfj-5x3c
Related
Published
2022-12-25T06:15:09Z
Modified
2023-11-29T09:47:04.942657Z
Details

PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5pacparse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."

References

Affected packages

Alpine:v3.14 / heimdal

Package

Name
heimdal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
7.7.1-r0

Affected versions

1.*

1.2.1-r0
1.2.1-r1
1.2.1-r2
1.2.1-r3
1.2.1-r4
1.3.1-r0
1.3.1-r1
1.3.1-r2
1.3.1-r3
1.3.1-r4
1.3.1-r5
1.3.3-r0
1.4-r0
1.4-r1
1.4-r2
1.4-r3
1.4-r4
1.4-r5
1.4-r6
1.4-r7
1.4-r8
1.4-r9
1.4-r10
1.4-r11
1.5-r2
1.5.2-r3
1.5.2-r4
1.5.2-r5
1.5.2-r6
1.5.2-r7
1.5.2-r8
1.5.3-r0
1.5.3-r1
1.6_rc2-r1

7.*

7.1.0-r1
7.4.0-r1
7.5.0-r1
7.7.0-r1

Alpine:v3.15 / heimdal

Package

Name
heimdal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
7.7.1-r0

Affected versions

1.*

1.2.1-r0
1.2.1-r1
1.2.1-r2
1.2.1-r3
1.2.1-r4
1.3.1-r0
1.3.1-r1
1.3.1-r2
1.3.1-r3
1.3.1-r4
1.3.1-r5
1.3.3-r0
1.4-r0
1.4-r1
1.4-r2
1.4-r3
1.4-r4
1.4-r5
1.4-r6
1.4-r7
1.4-r8
1.4-r9
1.4-r10
1.4-r11
1.5-r2
1.5.2-r3
1.5.2-r4
1.5.2-r5
1.5.2-r6
1.5.2-r7
1.5.2-r8
1.5.3-r0
1.5.3-r1
1.6_rc2-r1

7.*

7.1.0-r1
7.4.0-r1
7.5.0-r1
7.7.0-r1

Alpine:v3.15 / krb5

Package

Name
krb5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
1.19.4-r0

Affected versions

1.*

1.11-r0
1.11-r1
1.11-r2
1.11.2-r0
1.11.2-r1
1.11.2-r2
1.11.3-r0
1.11.4-r0
1.12.1-r0
1.12.2-r0
1.13-r0
1.13-r1
1.13.1-r0
1.13.1-r1
1.13.2-r0
1.13.2-r1
1.13.2-r2
1.14-r0
1.14-r1
1.14-r2
1.14.3-r0
1.14.3-r1
1.14.3-r2
1.15.1-r0
1.15.2-r0
1.15.2-r1
1.15.2-r2
1.15.3-r0
1.15.3-r1
1.15.4-r0
1.15.5-r0
1.17-r0
1.17.1-r0
1.18-r0
1.18.1-r0
1.18.2-r0
1.18.3-r0
1.18.3-r1
1.18.4-r0
1.19.2-r0
1.19.2-r1
1.19.2-r2
1.19.2-r3
1.19.2-r4
1.19.3-r4

Alpine:v3.15 / samba

Package

Name
samba

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
4.15.12-r0

Affected versions

3.*

3.2.8-r0
3.2.8-r1
3.2.10-r0
3.2.11-r0
3.2.11-r1
3.3.4-r0
3.3.5-r0
3.3.5-r1
3.3.5-r2
3.3.6-r0
3.3.7-r0
3.3.7-r1
3.3.7-r2
3.3.7-r3
3.3.7-r4
3.3.8-r0
3.4.3-r0
3.4.3-r1
3.4.4-r0
3.4.5-r0
3.4.5-r1
3.4.7-r0
3.4.7-r1
3.5.2-r0
3.5.3-r0
3.5.4-r0
3.5.4-r1
3.5.5-r0
3.5.6-r0
3.5.6-r1
3.5.6-r2
3.5.6-r3
3.5.6-r4
3.5.7-r0
3.5.8-r0
3.5.9-r0
3.5.9-r1
3.5.10-r0
3.5.11-r0
3.6.1-r0
3.6.1-r1
3.6.1-r2
3.6.2-r0
3.6.3-r0
3.6.4-r0
3.6.4-r1
3.6.5-r0
3.6.6-r0
3.6.7-r0
3.6.7-r1
3.6.8-r0
3.6.8-r1
3.6.9-r0
3.6.10-r0
3.6.11-r0
3.6.12-r0
3.6.13-r0
3.6.13-r1
3.6.15-r0
3.6.16-r0
3.6.19-r0
3.6.19-r1

4.*

4.1.0-r1
4.1.0-r2
4.1.1-r0
4.1.2-r0
4.1.3-r0
4.1.3-r1
4.1.3-r2
4.1.4-r0
4.1.5-r0
4.1.5-r1
4.1.6-r0
4.1.7-r0
4.1.8-r0
4.1.9-r0
4.1.10-r0
4.1.11-r0
4.1.12-r0
4.1.13-r0
4.1.14-r0
4.1.14-r1
4.1.15-r0
4.1.16-r0
4.1.17-r0
4.2.0-r0
4.2.0-r1
4.2.1-r0
4.2.1-r1
4.2.1-r2
4.2.3-r0
4.2.3-r1
4.2.3-r2
4.2.3-r3
4.2.7-r0
4.2.9-r0
4.2.9-r1
4.4.2-r0
4.4.2-r1
4.4.3-r0
4.4.4-r0
4.4.5-r0
4.4.5-r1
4.5.1-r0
4.5.3-r0
4.5.3-r1
4.5.4-r0
4.6.0-r0
4.6.1-r0
4.6.1-r1
4.6.1-r2
4.6.4-r0
4.6.5-r0
4.6.6-r0
4.6.6-r1
4.7.0-r0
4.7.0-r1
4.7.0-r2
4.7.1-r0
4.7.2-r0
4.7.3-r0
4.7.4-r0
4.7.6-r0
4.8.0-r0
4.8.1-r0
4.8.2-r0
4.8.2-r1
4.8.4-r0
4.8.4-r1
4.8.5-r0
4.8.7-r0
4.8.8-r0
4.8.11-r0
4.8.11-r1
4.10.2-r0
4.10.3-r0
4.10.4-r0
4.10.4-r1
4.10.5-r0
4.10.6-r0
4.10.8-r0
4.10.8-r1
4.11.1-r0
4.11.2-r0
4.11.2-r1
4.11.2-r2
4.11.3-r0
4.11.4-r0
4.11.4-r1
4.11.5-r0
4.11.6-r0
4.12.0-r0
4.12.1-r0
4.12.2-r0
4.12.2-r1
4.12.2-r2
4.12.5-r0
4.12.6-r0
4.12.7-r0
4.12.8-r0
4.12.9-r0
4.13.2-r0
4.13.2-r1
4.13.3-r0
4.13.3-r1
4.13.3-r2
4.13.5-r0
4.14.2-r0
4.14.2-r1
4.14.4-r0
4.14.5-r0
4.14.6-r0
4.14.6-r1
4.15.0-r0
4.15.1-r0
4.15.1-r1
4.15.2-r1
4.15.5-r1

Alpine:v3.16 / heimdal

Package

Name
heimdal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
7.7.1-r0

Affected versions

1.*

1.2.1-r0
1.2.1-r1
1.2.1-r2
1.2.1-r3
1.2.1-r4
1.3.1-r0
1.3.1-r1
1.3.1-r2
1.3.1-r3
1.3.1-r4
1.3.1-r5
1.3.3-r0
1.4-r0
1.4-r1
1.4-r2
1.4-r3
1.4-r4
1.4-r5
1.4-r6
1.4-r7
1.4-r8
1.4-r9
1.4-r10
1.4-r11
1.5-r2
1.5.2-r3
1.5.2-r4
1.5.2-r5
1.5.2-r6
1.5.2-r7
1.5.2-r8
1.5.3-r0
1.5.3-r1
1.6_rc2-r1

7.*

7.1.0-r1
7.4.0-r1
7.5.0-r1
7.7.0-r1

Alpine:v3.16 / krb5

Package

Name
krb5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
1.19.4-r0

Affected versions

1.*

1.11-r0
1.11-r1
1.11-r2
1.11.2-r0
1.11.2-r1
1.11.2-r2
1.11.3-r0
1.11.4-r0
1.12.1-r0
1.12.2-r0
1.13-r0
1.13-r1
1.13.1-r0
1.13.1-r1
1.13.2-r0
1.13.2-r1
1.13.2-r2
1.14-r0
1.14-r1
1.14-r2
1.14.3-r0
1.14.3-r1
1.14.3-r2
1.15.1-r0
1.15.2-r0
1.15.2-r1
1.15.2-r2
1.15.3-r0
1.15.3-r1
1.15.4-r0
1.15.5-r0
1.17-r0
1.17.1-r0
1.18-r0
1.18.1-r0
1.18.2-r0
1.18.3-r0
1.18.3-r1
1.18.4-r0
1.19.2-r0
1.19.2-r1
1.19.2-r2
1.19.2-r3
1.19.2-r4
1.19.3-r4

Alpine:v3.16 / samba

Package

Name
samba

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
4.15.12-r0

Affected versions

3.*

3.2.8-r0
3.2.8-r1
3.2.10-r0
3.2.11-r0
3.2.11-r1
3.3.4-r0
3.3.5-r0
3.3.5-r1
3.3.5-r2
3.3.6-r0
3.3.7-r0
3.3.7-r1
3.3.7-r2
3.3.7-r3
3.3.7-r4
3.3.8-r0
3.4.3-r0
3.4.3-r1
3.4.4-r0
3.4.5-r0
3.4.5-r1
3.4.7-r0
3.4.7-r1
3.5.2-r0
3.5.3-r0
3.5.4-r0
3.5.4-r1
3.5.5-r0
3.5.6-r0
3.5.6-r1
3.5.6-r2
3.5.6-r3
3.5.6-r4
3.5.7-r0
3.5.8-r0
3.5.9-r0
3.5.9-r1
3.5.10-r0
3.5.11-r0
3.6.1-r0
3.6.1-r1
3.6.1-r2
3.6.2-r0
3.6.3-r0
3.6.4-r0
3.6.4-r1
3.6.5-r0
3.6.6-r0
3.6.7-r0
3.6.7-r1
3.6.8-r0
3.6.8-r1
3.6.9-r0
3.6.10-r0
3.6.11-r0
3.6.12-r0
3.6.13-r0
3.6.13-r1
3.6.15-r0
3.6.16-r0
3.6.19-r0
3.6.19-r1

4.*

4.1.0-r1
4.1.0-r2
4.1.1-r0
4.1.2-r0
4.1.3-r0
4.1.3-r1
4.1.3-r2
4.1.4-r0
4.1.5-r0
4.1.5-r1
4.1.6-r0
4.1.7-r0
4.1.8-r0
4.1.9-r0
4.1.10-r0
4.1.11-r0
4.1.12-r0
4.1.13-r0
4.1.14-r0
4.1.14-r1
4.1.15-r0
4.1.16-r0
4.1.17-r0
4.2.0-r0
4.2.0-r1
4.2.1-r0
4.2.1-r1
4.2.1-r2
4.2.3-r0
4.2.3-r1
4.2.3-r2
4.2.3-r3
4.2.7-r0
4.2.9-r0
4.2.9-r1
4.4.2-r0
4.4.2-r1
4.4.3-r0
4.4.4-r0
4.4.5-r0
4.4.5-r1
4.5.1-r0
4.5.3-r0
4.5.3-r1
4.5.4-r0
4.6.0-r0
4.6.1-r0
4.6.1-r1
4.6.1-r2
4.6.4-r0
4.6.5-r0
4.6.6-r0
4.6.6-r1
4.7.0-r0
4.7.0-r1
4.7.0-r2
4.7.1-r0
4.7.2-r0
4.7.3-r0
4.7.4-r0
4.7.6-r0
4.8.0-r0
4.8.1-r0
4.8.2-r0
4.8.2-r1
4.8.4-r0
4.8.4-r1
4.8.5-r0
4.8.7-r0
4.8.8-r0
4.8.11-r0
4.8.11-r1
4.10.2-r0
4.10.3-r0
4.10.4-r0
4.10.4-r1
4.10.5-r0
4.10.6-r0
4.10.8-r0
4.10.8-r1
4.11.1-r0
4.11.2-r0
4.11.2-r1
4.11.2-r2
4.11.3-r0
4.11.4-r0
4.11.4-r1
4.11.5-r0
4.11.6-r0
4.12.0-r0
4.12.1-r0
4.12.2-r0
4.12.2-r1
4.12.2-r2
4.12.5-r0
4.12.6-r0
4.12.7-r0
4.12.8-r0
4.12.9-r0
4.13.2-r0
4.13.2-r1
4.13.3-r0
4.13.3-r1
4.13.3-r2
4.13.5-r0
4.14.2-r0
4.14.2-r1
4.14.4-r0
4.14.5-r0
4.14.6-r0
4.14.6-r1
4.15.0-r0
4.15.1-r0
4.15.1-r1
4.15.2-r0
4.15.3-r0
4.15.3-r1
4.15.5-r0
4.15.5-r1
4.15.6-r1
4.15.7-r1

Alpine:v3.17 / heimdal

Package

Name
heimdal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
7.7.1-r0

Affected versions

1.*

1.2.1-r0
1.2.1-r1
1.2.1-r2
1.2.1-r3
1.2.1-r4
1.3.1-r0
1.3.1-r1
1.3.1-r2
1.3.1-r3
1.3.1-r4
1.3.1-r5
1.3.3-r0
1.4-r0
1.4-r1
1.4-r2
1.4-r3
1.4-r4
1.4-r5
1.4-r6
1.4-r7
1.4-r8
1.4-r9
1.4-r10
1.4-r11
1.5-r2
1.5.2-r3
1.5.2-r4
1.5.2-r5
1.5.2-r6
1.5.2-r7
1.5.2-r8
1.5.3-r0
1.5.3-r1
1.6_rc2-r1

7.*

7.1.0-r1
7.4.0-r1
7.5.0-r1
7.7.0-r1

Alpine:v3.17 / krb5

Package

Name
krb5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
1.20.1-r0

Affected versions

1.*

1.11-r0
1.11-r1
1.11-r2
1.11.2-r0
1.11.2-r1
1.11.2-r2
1.11.3-r0
1.11.4-r0
1.12.1-r0
1.12.2-r0
1.13-r0
1.13-r1
1.13.1-r0
1.13.1-r1
1.13.2-r0
1.13.2-r1
1.13.2-r2
1.14-r0
1.14-r1
1.14-r2
1.14.3-r0
1.14.3-r1
1.14.3-r2
1.15.1-r0
1.15.2-r0
1.15.2-r1
1.15.2-r2
1.15.3-r0
1.15.3-r1
1.15.4-r0
1.15.5-r0
1.17-r0
1.17.1-r0
1.18-r0
1.18.1-r0
1.18.2-r0
1.18.3-r0
1.18.3-r1
1.18.4-r0
1.19.2-r0
1.19.2-r1
1.19.2-r2
1.19.2-r3
1.19.2-r4
1.19.3-r0
1.19.3-r1
1.19.3-r2
1.20-r2

Alpine:v3.18 / heimdal

Package

Name
heimdal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
7.7.1-r0

Affected versions

1.*

1.2.1-r0
1.2.1-r1
1.2.1-r2
1.2.1-r3
1.2.1-r4
1.3.1-r0
1.3.1-r1
1.3.1-r2
1.3.1-r3
1.3.1-r4
1.3.1-r5
1.3.3-r0
1.4-r0
1.4-r1
1.4-r2
1.4-r3
1.4-r4
1.4-r5
1.4-r6
1.4-r7
1.4-r8
1.4-r9
1.4-r10
1.4-r11
1.5-r2
1.5.2-r3
1.5.2-r4
1.5.2-r5
1.5.2-r6
1.5.2-r7
1.5.2-r8
1.5.3-r0
1.5.3-r1
1.6_rc2-r1

7.*

7.1.0-r1
7.4.0-r1
7.5.0-r1
7.7.0-r1

Alpine:v3.18 / krb5

Package

Name
krb5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
1.20.1-r0

Affected versions

1.*

1.11-r0
1.11-r1
1.11-r2
1.11.2-r0
1.11.2-r1
1.11.2-r2
1.11.3-r0
1.11.4-r0
1.12.1-r0
1.12.2-r0
1.13-r0
1.13-r1
1.13.1-r0
1.13.1-r1
1.13.2-r0
1.13.2-r1
1.13.2-r2
1.14-r0
1.14-r1
1.14-r2
1.14.3-r0
1.14.3-r1
1.14.3-r2
1.15.1-r0
1.15.2-r0
1.15.2-r1
1.15.2-r2
1.15.3-r0
1.15.3-r1
1.15.4-r0
1.15.5-r0
1.17-r0
1.17.1-r0
1.18-r0
1.18.1-r0
1.18.2-r0
1.18.3-r0
1.18.3-r1
1.18.4-r0
1.19.2-r0
1.19.2-r1
1.19.2-r2
1.19.2-r3
1.19.2-r4
1.19.3-r0
1.19.3-r1
1.19.3-r2
1.20-r2

Alpine:v3.18 / samba

Package

Name
samba

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
4.16.7-r0

Affected versions

3.*

3.2.8-r0
3.2.8-r1
3.2.10-r0
3.2.11-r0
3.2.11-r1
3.3.4-r0
3.3.5-r0
3.3.5-r1
3.3.5-r2
3.3.6-r0
3.3.7-r0
3.3.7-r1
3.3.7-r2
3.3.7-r3
3.3.7-r4
3.3.8-r0
3.4.3-r0
3.4.3-r1
3.4.4-r0
3.4.5-r0
3.4.5-r1
3.4.7-r0
3.4.7-r1
3.5.2-r0
3.5.3-r0
3.5.4-r0
3.5.4-r1
3.5.5-r0
3.5.6-r0
3.5.6-r1
3.5.6-r2
3.5.6-r3
3.5.6-r4
3.5.7-r0
3.5.8-r0
3.5.9-r0
3.5.9-r1
3.5.10-r0
3.5.11-r0
3.6.1-r0
3.6.1-r1
3.6.1-r2
3.6.2-r0
3.6.3-r0
3.6.4-r0
3.6.4-r1
3.6.5-r0
3.6.6-r0
3.6.7-r0
3.6.7-r1
3.6.8-r0
3.6.8-r1
3.6.9-r0
3.6.10-r0
3.6.11-r0
3.6.12-r0
3.6.13-r0
3.6.13-r1
3.6.15-r0
3.6.16-r0
3.6.19-r0
3.6.19-r1

4.*

4.1.0-r1
4.1.0-r2
4.1.1-r0
4.1.2-r0
4.1.3-r0
4.1.3-r1
4.1.3-r2
4.1.4-r0
4.1.5-r0
4.1.5-r1
4.1.6-r0
4.1.7-r0
4.1.8-r0
4.1.9-r0
4.1.10-r0
4.1.11-r0
4.1.12-r0
4.1.13-r0
4.1.14-r0
4.1.14-r1
4.1.15-r0
4.1.16-r0
4.1.17-r0
4.2.0-r0
4.2.0-r1
4.2.1-r0
4.2.1-r1
4.2.1-r2
4.2.3-r0
4.2.3-r1
4.2.3-r2
4.2.3-r3
4.2.7-r0
4.2.9-r0
4.2.9-r1
4.4.2-r0
4.4.2-r1
4.4.3-r0
4.4.4-r0
4.4.5-r0
4.4.5-r1
4.5.1-r0
4.5.3-r0
4.5.3-r1
4.5.4-r0
4.6.0-r0
4.6.1-r0
4.6.1-r1
4.6.1-r2
4.6.4-r0
4.6.5-r0
4.6.6-r0
4.6.6-r1
4.7.0-r0
4.7.0-r1
4.7.0-r2
4.7.1-r0
4.7.2-r0
4.7.3-r0
4.7.4-r0
4.7.6-r0
4.8.0-r0
4.8.1-r0
4.8.2-r0
4.8.2-r1
4.8.4-r0
4.8.4-r1
4.8.5-r0
4.8.7-r0
4.8.8-r0
4.8.11-r0
4.8.11-r1
4.10.2-r0
4.10.3-r0
4.10.4-r0
4.10.4-r1
4.10.5-r0
4.10.6-r0
4.10.8-r0
4.10.8-r1
4.11.1-r0
4.11.2-r0
4.11.2-r1
4.11.2-r2
4.11.3-r0
4.11.4-r0
4.11.4-r1
4.11.5-r0
4.11.6-r0
4.12.0-r0
4.12.1-r0
4.12.2-r0
4.12.2-r1
4.12.2-r2
4.12.5-r0
4.12.6-r0
4.12.7-r0
4.12.8-r0
4.12.9-r0
4.13.2-r0
4.13.2-r1
4.13.3-r0
4.13.3-r1
4.13.3-r2
4.13.5-r0
4.14.2-r0
4.14.2-r1
4.14.4-r0
4.14.5-r0
4.14.6-r0
4.14.6-r1
4.15.0-r0
4.15.1-r0
4.15.1-r1
4.15.2-r0
4.15.3-r0
4.15.3-r1
4.15.5-r0
4.15.5-r1
4.15.6-r0
4.15.7-r0
4.15.7-r1
4.15.9-r0
4.16.4-r0
4.16.6-r0

Git / github.com/heimdal/heimdal

Affected ranges

Type
GIT
Repo
https://github.com/heimdal/heimdal
Events
Introduced
0The exact introduced commit is unknown
Fixed
Type
GIT
Repo
https://github.com/krb5/krb5
Events
Type
GIT
Repo
https://github.com/samba-team/samba
Events

Affected versions

Other

git2svn-syncpoint-master
switch-from-svn-to-git

heimdal-1.*

heimdal-1.3.0pre1
heimdal-1.3.0pre10
heimdal-1.3.0pre11
heimdal-1.3.0pre3
heimdal-1.3.0pre4
heimdal-1.3.0pre5
heimdal-1.3.0pre6
heimdal-1.3.0pre7
heimdal-1.3.0pre8
heimdal-1.3.0pre9
heimdal-1.3.0rc1
heimdal-1.5pre1
heimdal-1.5pre2

heimdal-7.*

heimdal-7.0.1
heimdal-7.0.2
heimdal-7.0.3
heimdal-7.1.0
heimdal-7.1rc1
heimdal-7.2.0
heimdal-7.3.0
heimdal-7.4.0
heimdal-7.5.0
heimdal-7.6.0
heimdal-7.7.0

samba-4.*

samba-4.17.0
samba-4.17.1
samba-4.17.2

upstream-1.*

upstream-1.4.0+git20101228.dfsg.1
upstream-1.4.0+git20110220.dfsg.1