UBUNTU-CVE-2017-17439

See a problem?
Source
https://ubuntu.com/security/notices/UBUNTU-CVE-2017-17439
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-17439.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2017-17439
Related
Published
2017-12-06T15:29:00Z
Modified
2017-12-06T15:29:00Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet containing empty data fields for client name or realm. The parser would unconditionally dereference NULL pointers in that case, leading to a segmentation fault. This is related to the kdcasrep function in kdc/kerberos5.c and the derlengthvisiblestring function in lib/asn1/der_length.c.

References

Affected packages

Ubuntu:18.04:LTS / heimdal

Package

Name
heimdal
Purl
pkg:deb/ubuntu/heimdal@7.5.0+dfsg-1?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.5.0+dfsg-1

Affected versions

7.*

7.4.0.dfsg.1-2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "libasn1-8-heimdal-dbgsym": "7.5.0+dfsg-1",
            "libhdb9-heimdal-dbgsym": "7.5.0+dfsg-1",
            "libhcrypto4-heimdal": "7.5.0+dfsg-1",
            "libhx509-5-heimdal-dbgsym": "7.5.0+dfsg-1",
            "libgssapi3-heimdal-dbgsym": "7.5.0+dfsg-1",
            "libheimbase1-heimdal-dbgsym": "7.5.0+dfsg-1",
            "libheimntlm0-heimdal-dbgsym": "7.5.0+dfsg-1",
            "libotp0-heimdal": "7.5.0+dfsg-1",
            "heimdal-kcm": "7.5.0+dfsg-1",
            "libheimbase1-heimdal": "7.5.0+dfsg-1",
            "libotp0-heimdal-dbgsym": "7.5.0+dfsg-1",
            "heimdal-multidev-dbgsym": "7.5.0+dfsg-1",
            "heimdal-servers": "7.5.0+dfsg-1",
            "heimdal-dev": "7.5.0+dfsg-1",
            "libkdc2-heimdal-dbgsym": "7.5.0+dfsg-1",
            "heimdal-kcm-dbgsym": "7.5.0+dfsg-1",
            "heimdal-kdc": "7.5.0+dfsg-1",
            "libsl0-heimdal-dbgsym": "7.5.0+dfsg-1",
            "libkadm5clnt7-heimdal": "7.5.0+dfsg-1",
            "heimdal-kdc-dbgsym": "7.5.0+dfsg-1",
            "libkadm5clnt7-heimdal-dbgsym": "7.5.0+dfsg-1",
            "libasn1-8-heimdal": "7.5.0+dfsg-1",
            "heimdal-clients": "7.5.0+dfsg-1",
            "libhdb9-heimdal": "7.5.0+dfsg-1",
            "libgssapi3-heimdal": "7.5.0+dfsg-1",
            "libkafs0-heimdal-dbgsym": "7.5.0+dfsg-1",
            "libkadm5srv8-heimdal-dbgsym": "7.5.0+dfsg-1",
            "libkadm5srv8-heimdal": "7.5.0+dfsg-1",
            "libsl0-heimdal": "7.5.0+dfsg-1",
            "heimdal-clients-dbgsym": "7.5.0+dfsg-1",
            "heimdal-servers-dbgsym": "7.5.0+dfsg-1",
            "libkrb5-26-heimdal": "7.5.0+dfsg-1",
            "heimdal-docs": "7.5.0+dfsg-1",
            "libkrb5-26-heimdal-dbgsym": "7.5.0+dfsg-1",
            "libwind0-heimdal": "7.5.0+dfsg-1",
            "libroken18-heimdal": "7.5.0+dfsg-1",
            "libkafs0-heimdal": "7.5.0+dfsg-1",
            "libhcrypto4-heimdal-dbgsym": "7.5.0+dfsg-1",
            "libwind0-heimdal-dbgsym": "7.5.0+dfsg-1",
            "libheimntlm0-heimdal": "7.5.0+dfsg-1",
            "libroken18-heimdal-dbgsym": "7.5.0+dfsg-1",
            "libhx509-5-heimdal": "7.5.0+dfsg-1",
            "libkdc2-heimdal": "7.5.0+dfsg-1",
            "heimdal-multidev": "7.5.0+dfsg-1"
        }
    ]
}