USN-5800-1

Source
https://ubuntu.com/security/notices/USN-5800-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/USN-5800-1.json
Related
Published
2023-01-12T17:12:53.432298Z
Modified
2023-01-12T17:12:53.432298Z
Summary
heimdal vulnerabilities
Details

It was discovered that Heimdal incorrectly handled certain SPNEGO tokens. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2021-44758)

Evgeny Legerov discovered that Heimdal incorrectly handled memory when performing certain DES decryption operations. A remote attacker could use this issue to cause a denial of service, or possibly execute arbitrary code. (CVE-2022-3437)

Greg Hudson discovered that Kerberos PAC implementation used in Heimdal incorrectly handled certain parsing operations. A remote attacker could use this issue to cause a denial of service, or possibly execute arbitrary code. (CVE-2022-42898)

It was discovered that Heimdal's KDC did not properly handle certain error conditions. A remote attacker could use this issue to cause a denial of service, or possibly execute arbitrary code. (CVE-2022-44640)

References

Affected packages

Ubuntu:20.04:LTS / heimdal

Package

Name
heimdal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
7.7.0+dfsg-1ubuntu1.3

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "libasn1-8-heimdal": "7.7.0+dfsg-1ubuntu1.3",
            "heimdal-clients": "7.7.0+dfsg-1ubuntu1.3",
            "libhdb9-heimdal": "7.7.0+dfsg-1ubuntu1.3",
            "libgssapi3-heimdal": "7.7.0+dfsg-1ubuntu1.3",
            "libkrb5-26-heimdal": "7.7.0+dfsg-1ubuntu1.3",
            "libsl0-heimdal": "7.7.0+dfsg-1ubuntu1.3",
            "libkadm5srv8-heimdal": "7.7.0+dfsg-1ubuntu1.3",
            "heimdal-servers": "7.7.0+dfsg-1ubuntu1.3",
            "libhcrypto4-heimdal": "7.7.0+dfsg-1ubuntu1.3",
            "libotp0-heimdal": "7.7.0+dfsg-1ubuntu1.3",
            "heimdal-docs": "7.7.0+dfsg-1ubuntu1.3",
            "libwind0-heimdal": "7.7.0+dfsg-1ubuntu1.3",
            "heimdal-kcm": "7.7.0+dfsg-1ubuntu1.3",
            "libkafs0-heimdal": "7.7.0+dfsg-1ubuntu1.3",
            "libheimbase1-heimdal": "7.7.0+dfsg-1ubuntu1.3",
            "libroken18-heimdal": "7.7.0+dfsg-1ubuntu1.3",
            "heimdal-dev": "7.7.0+dfsg-1ubuntu1.3",
            "libkdc2-heimdal": "7.7.0+dfsg-1ubuntu1.3",
            "heimdal-kdc": "7.7.0+dfsg-1ubuntu1.3",
            "libhx509-5-heimdal": "7.7.0+dfsg-1ubuntu1.3",
            "libheimntlm0-heimdal": "7.7.0+dfsg-1ubuntu1.3",
            "libkadm5clnt7-heimdal": "7.7.0+dfsg-1ubuntu1.3",
            "heimdal-multidev": "7.7.0+dfsg-1ubuntu1.3"
        }
    ]
}

Ubuntu:Pro:14.04:LTS / heimdal

Package

Name
heimdal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
1.6~git20131207+dfsg-1ubuntu1.2+esm3

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "libasn1-8-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "heimdal-clients": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "libhdb9-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "libgssapi3-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "libkrb5-26-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "libsl0-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "libkadm5srv8-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "heimdal-servers": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "libhcrypto4-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "libotp0-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "heimdal-clients-x": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "heimdal-docs": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "libwind0-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "heimdal-kcm": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "libkafs0-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "libheimbase1-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "libroken18-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "heimdal-servers-x": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "heimdal-dev": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "libkdc2-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "heimdal-kdc": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "libhx509-5-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "libheimntlm0-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "libkadm5clnt7-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm3",
            "heimdal-multidev": "1.6~git20131207+dfsg-1ubuntu1.2+esm3"
        }
    ]
}

Ubuntu:18.04:LTS / heimdal

Package

Name
heimdal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
7.5.0+dfsg-1ubuntu0.3

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "libasn1-8-heimdal": "7.5.0+dfsg-1ubuntu0.3",
            "heimdal-clients": "7.5.0+dfsg-1ubuntu0.3",
            "libhdb9-heimdal": "7.5.0+dfsg-1ubuntu0.3",
            "libgssapi3-heimdal": "7.5.0+dfsg-1ubuntu0.3",
            "libkrb5-26-heimdal": "7.5.0+dfsg-1ubuntu0.3",
            "libsl0-heimdal": "7.5.0+dfsg-1ubuntu0.3",
            "libkadm5srv8-heimdal": "7.5.0+dfsg-1ubuntu0.3",
            "heimdal-servers": "7.5.0+dfsg-1ubuntu0.3",
            "libhcrypto4-heimdal": "7.5.0+dfsg-1ubuntu0.3",
            "libotp0-heimdal": "7.5.0+dfsg-1ubuntu0.3",
            "heimdal-docs": "7.5.0+dfsg-1ubuntu0.3",
            "libwind0-heimdal": "7.5.0+dfsg-1ubuntu0.3",
            "heimdal-kcm": "7.5.0+dfsg-1ubuntu0.3",
            "libkafs0-heimdal": "7.5.0+dfsg-1ubuntu0.3",
            "libheimbase1-heimdal": "7.5.0+dfsg-1ubuntu0.3",
            "libroken18-heimdal": "7.5.0+dfsg-1ubuntu0.3",
            "heimdal-dev": "7.5.0+dfsg-1ubuntu0.3",
            "libkdc2-heimdal": "7.5.0+dfsg-1ubuntu0.3",
            "heimdal-kdc": "7.5.0+dfsg-1ubuntu0.3",
            "libhx509-5-heimdal": "7.5.0+dfsg-1ubuntu0.3",
            "libheimntlm0-heimdal": "7.5.0+dfsg-1ubuntu0.3",
            "libkadm5clnt7-heimdal": "7.5.0+dfsg-1ubuntu0.3",
            "heimdal-multidev": "7.5.0+dfsg-1ubuntu0.3"
        }
    ]
}

Ubuntu:Pro:16.04:LTS / heimdal

Package

Name
heimdal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "libasn1-8-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "heimdal-clients": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "libhdb9-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "libgssapi3-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "libkrb5-26-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "libsl0-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "libkadm5srv8-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "heimdal-servers": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "libhcrypto4-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "libotp0-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "heimdal-docs": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "libwind0-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "heimdal-kcm": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "libkafs0-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "libheimbase1-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "libroken18-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "heimdal-dev": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "libkdc2-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "heimdal-kdc": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "libhx509-5-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "libheimntlm0-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "libkadm5clnt7-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3",
            "heimdal-multidev": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3"
        }
    ]
}