MGASA-2017-0265

Source
https://advisories.mageia.org/MGASA-2017-0265.html
Import Source
https://advisories.mageia.org/MGASA-2017-0265.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2017-0265
Related
Published
2017-08-13T13:36:42Z
Modified
2017-08-13T13:20:31Z
Summary
Updated heimdal packages fix security vulnerability
Details

Jeffrey Altman, Viktor Dukhovni, and Nicolas Williams discovered that Heimdal clients incorrectly trusted unauthenticated portions of Kerberos tickets. A remote attacker could use this to impersonate trusted network services or perform other attacks (CVE-2017-11103).

References
Credits

Affected packages

Mageia:6 / heimdal

Package

Name
heimdal
Purl
pkg:rpm/mageia/heimdal?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.3.0-1.1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / heimdal

Package

Name
heimdal
Purl
pkg:rpm/mageia/heimdal?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.5.3-6.1.mga5

Ecosystem specific

{
    "section": "core"
}