UBUNTU-CVE-2017-17439

Source
https://ubuntu.com/security/CVE-2017-17439
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-17439.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2017-17439
Related
Published
2017-12-06T15:29:00Z
Modified
2017-12-06T15:29:00Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet containing empty data fields for client name or realm. The parser would unconditionally dereference NULL pointers in that case, leading to a segmentation fault. This is related to the kdcasrep function in kdc/kerberos5.c and the derlengthvisiblestring function in lib/asn1/der_length.c.

References

Affected packages

Ubuntu:18.04:LTS / heimdal

Package

Name
heimdal
Purl
pkg:deb/ubuntu/heimdal?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.5.0+dfsg-1

Affected versions

7.*

7.4.0.dfsg.1-2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "heimdal-clients"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "heimdal-clients-dbgsym"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "heimdal-dev"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "heimdal-docs"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "heimdal-kcm"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "heimdal-kcm-dbgsym"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "heimdal-kdc"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "heimdal-kdc-dbgsym"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "heimdal-multidev"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "heimdal-multidev-dbgsym"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "heimdal-servers"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "heimdal-servers-dbgsym"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libasn1-8-heimdal"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libasn1-8-heimdal-dbgsym"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libgssapi3-heimdal"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libgssapi3-heimdal-dbgsym"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libhcrypto4-heimdal"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libhcrypto4-heimdal-dbgsym"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libhdb9-heimdal"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libhdb9-heimdal-dbgsym"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libheimbase1-heimdal"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libheimbase1-heimdal-dbgsym"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libheimntlm0-heimdal"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libheimntlm0-heimdal-dbgsym"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libhx509-5-heimdal"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libhx509-5-heimdal-dbgsym"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libkadm5clnt7-heimdal"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libkadm5clnt7-heimdal-dbgsym"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libkadm5srv8-heimdal"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libkadm5srv8-heimdal-dbgsym"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libkafs0-heimdal"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libkafs0-heimdal-dbgsym"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libkdc2-heimdal"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libkdc2-heimdal-dbgsym"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libkrb5-26-heimdal"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libkrb5-26-heimdal-dbgsym"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libotp0-heimdal"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libotp0-heimdal-dbgsym"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libroken18-heimdal"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libroken18-heimdal-dbgsym"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libsl0-heimdal"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libsl0-heimdal-dbgsym"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libwind0-heimdal"
        },
        {
            "binary_version": "7.5.0+dfsg-1",
            "binary_name": "libwind0-heimdal-dbgsym"
        }
    ]
}