UBUNTU-CVE-2017-6594

Source
https://ubuntu.com/security/CVE-2017-6594
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-6594.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2017-6594
Upstream
Published
2017-08-28T19:29:00Z
Modified
2025-09-08T16:44:09Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
  • Ubuntu - low
Summary
[none]
Details

The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath policy protection mechanism by leveraging failure to add the previous hop realm to the transit path of issued tickets.

References

Affected packages

Ubuntu:Pro:14.04:LTS / heimdal

Package

Name
heimdal
Purl
pkg:deb/ubuntu/heimdal@1.6~git20131207+dfsg-1ubuntu1.2+esm4?arch=source&distro=esm-infra-legacy/trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.6~git20120403+dfsg1-3ubuntu0.1
1.6~git20120403+dfsg1-3ubuntu0.2
1.6~git20131207+dfsg-1ubuntu1
1.6~git20131207+dfsg-1ubuntu1.1
1.6~git20131207+dfsg-1ubuntu1.2
1.6~git20131207+dfsg-1ubuntu1.2+esm1
1.6~git20131207+dfsg-1ubuntu1.2+esm2
1.6~git20131207+dfsg-1ubuntu1.2+esm3
1.6~git20131207+dfsg-1ubuntu1.2+esm4

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "heimdal-clients",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "heimdal-clients-x",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "heimdal-dev",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "heimdal-docs",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "heimdal-kcm",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "heimdal-kdc",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "heimdal-multidev",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "heimdal-servers",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "heimdal-servers-x",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "libasn1-8-heimdal",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "libgssapi3-heimdal",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "libhcrypto4-heimdal",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "libhdb9-heimdal",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "libheimbase1-heimdal",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "libheimntlm0-heimdal",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "libhx509-5-heimdal",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "libkadm5clnt7-heimdal",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "libkadm5srv8-heimdal",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "libkafs0-heimdal",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "libkdc2-heimdal",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "libkrb5-26-heimdal",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "libotp0-heimdal",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "libroken18-heimdal",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "libsl0-heimdal",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        },
        {
            "binary_name": "libwind0-heimdal",
            "binary_version": "1.6~git20131207+dfsg-1ubuntu1.2+esm4"
        }
    ]
}

Ubuntu:Pro:16.04:LTS / heimdal

Package

Name
heimdal
Purl
pkg:deb/ubuntu/heimdal@1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.6~rc2+dfsg-10ubuntu1
1.7~git20150920+dfsg-4ubuntu1
1.7~git20150920+dfsg-4ubuntu1.16.04.1
1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1
1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm2
1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3
1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "heimdal-clients",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "heimdal-dev",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "heimdal-docs",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "heimdal-kcm",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "heimdal-kdc",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "heimdal-multidev",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "heimdal-servers",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "libasn1-8-heimdal",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "libgssapi3-heimdal",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "libhcrypto4-heimdal",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "libhdb9-heimdal",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "libheimbase1-heimdal",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "libheimntlm0-heimdal",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "libhx509-5-heimdal",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "libkadm5clnt7-heimdal",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "libkadm5srv8-heimdal",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "libkafs0-heimdal",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "libkdc2-heimdal",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "libkrb5-26-heimdal",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "libotp0-heimdal",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "libroken18-heimdal",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "libsl0-heimdal",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        },
        {
            "binary_name": "libwind0-heimdal",
            "binary_version": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4"
        }
    ]
}