USN-5675-1

Source
https://ubuntu.com/security/notices/USN-5675-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/USN-5675-1.json
Related
Published
2022-10-13T18:39:02.324742Z
Modified
2022-10-13T18:39:02.324742Z
Details

Isaac Boukris and Andrew Bartlett discovered that Heimdal's KDC was not properly performing checksum algorithm verifications in the S4U2Self extension module. An attacker could possibly use this issue to perform a machine-in-the-middle attack and request S4U2Self tickets for any user known by the application. This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2018-16860)

It was discovered that Heimdal was not properly handling the verification of key exchanges when an anonymous PKINIT was being used. An attacker could possibly use this issue to perform a machine-in-the-middle attack and expose sensitive information. This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2019-12098)

Joseph Sutton discovered that Heimdal was not properly handling memory management operations when dealing with TGS-REQ tickets that were missing information. An attacker could possibly use this issue to cause a denial of service. (CVE-2021-3671)

Michał Kępień discovered that Heimdal was not properly handling logical conditions that related to memory management operations. An attacker could possibly use this issue to cause a denial of service. (CVE-2022-3116)

References

Affected packages

Ubuntu:20.04:LTS / heimdal

Package

Name
heimdal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
7.7.0+dfsg-1ubuntu1.1

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "libasn1-8-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "heimdal-clients": "7.7.0+dfsg-1ubuntu1.1",
            "libhdb9-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "libgssapi3-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "libkrb5-26-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "libsl0-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "libkadm5srv8-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "heimdal-servers": "7.7.0+dfsg-1ubuntu1.1",
            "libhcrypto4-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "libotp0-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "heimdal-docs": "7.7.0+dfsg-1ubuntu1.1",
            "libwind0-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "heimdal-kcm": "7.7.0+dfsg-1ubuntu1.1",
            "libkafs0-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "libheimbase1-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "libroken18-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "heimdal-dev": "7.7.0+dfsg-1ubuntu1.1",
            "libkdc2-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "heimdal-kdc": "7.7.0+dfsg-1ubuntu1.1",
            "libhx509-5-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "libheimntlm0-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "libkadm5clnt7-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "heimdal-multidev": "7.7.0+dfsg-1ubuntu1.1"
        }
    ]
}

Ubuntu:Pro:14.04:LTS / heimdal

Package

Name
heimdal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
1.6~git20131207+dfsg-1ubuntu1.2+esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "libasn1-8-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-clients": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libhdb9-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libgssapi3-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkrb5-26-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libsl0-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkadm5srv8-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-servers": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libhcrypto4-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libotp0-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-clients-x": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-docs": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libwind0-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-kcm": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkafs0-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libheimbase1-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libroken18-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-servers-x": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-dev": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkdc2-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-kdc": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libhx509-5-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libheimntlm0-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkadm5clnt7-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-multidev": "1.6~git20131207+dfsg-1ubuntu1.2+esm1"
        }
    ]
}

Ubuntu:18.04:LTS / heimdal

Package

Name
heimdal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
7.5.0+dfsg-1ubuntu0.1

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "libasn1-8-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-clients": "7.5.0+dfsg-1ubuntu0.1",
            "libhdb9-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libgssapi3-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libkrb5-26-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libsl0-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libkadm5srv8-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-servers": "7.5.0+dfsg-1ubuntu0.1",
            "libhcrypto4-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libotp0-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-docs": "7.5.0+dfsg-1ubuntu0.1",
            "libwind0-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-kcm": "7.5.0+dfsg-1ubuntu0.1",
            "libkafs0-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libheimbase1-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libroken18-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-dev": "7.5.0+dfsg-1ubuntu0.1",
            "libkdc2-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-kdc": "7.5.0+dfsg-1ubuntu0.1",
            "libhx509-5-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libheimntlm0-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libkadm5clnt7-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-multidev": "7.5.0+dfsg-1ubuntu0.1"
        }
    ]
}

Ubuntu:Pro:16.04:LTS / heimdal

Package

Name
heimdal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "libasn1-8-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-clients": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libhdb9-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libgssapi3-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkrb5-26-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libsl0-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkadm5srv8-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-servers": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libhcrypto4-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libotp0-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-docs": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libwind0-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-kcm": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkafs0-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libheimbase1-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libroken18-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-dev": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkdc2-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-kdc": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libhx509-5-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libheimntlm0-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkadm5clnt7-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-multidev": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1"
        }
    ]
}