In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet containing empty data fields for client name or realm. The parser would unconditionally dereference NULL pointers in that case, leading to a segmentation fault. This is related to the kdcasrep function in kdc/kerberos5.c and the derlengthvisiblestring function in lib/asn1/der_length.c.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "libasn1-8-heimdal-dbgsym": "7.5.0+dfsg-1", "libhdb9-heimdal-dbgsym": "7.5.0+dfsg-1", "libhcrypto4-heimdal": "7.5.0+dfsg-1", "libhx509-5-heimdal-dbgsym": "7.5.0+dfsg-1", "libgssapi3-heimdal-dbgsym": "7.5.0+dfsg-1", "libheimbase1-heimdal-dbgsym": "7.5.0+dfsg-1", "libheimntlm0-heimdal-dbgsym": "7.5.0+dfsg-1", "libotp0-heimdal": "7.5.0+dfsg-1", "heimdal-kcm": "7.5.0+dfsg-1", "libheimbase1-heimdal": "7.5.0+dfsg-1", "libotp0-heimdal-dbgsym": "7.5.0+dfsg-1", "heimdal-multidev-dbgsym": "7.5.0+dfsg-1", "heimdal-servers": "7.5.0+dfsg-1", "heimdal-dev": "7.5.0+dfsg-1", "libkdc2-heimdal-dbgsym": "7.5.0+dfsg-1", "heimdal-kcm-dbgsym": "7.5.0+dfsg-1", "heimdal-kdc": "7.5.0+dfsg-1", "libsl0-heimdal-dbgsym": "7.5.0+dfsg-1", "libkadm5clnt7-heimdal": "7.5.0+dfsg-1", "heimdal-kdc-dbgsym": "7.5.0+dfsg-1", "libkadm5clnt7-heimdal-dbgsym": "7.5.0+dfsg-1", "libasn1-8-heimdal": "7.5.0+dfsg-1", "heimdal-clients": "7.5.0+dfsg-1", "libhdb9-heimdal": "7.5.0+dfsg-1", "libgssapi3-heimdal": "7.5.0+dfsg-1", "libkafs0-heimdal-dbgsym": "7.5.0+dfsg-1", "libkadm5srv8-heimdal-dbgsym": "7.5.0+dfsg-1", "libkadm5srv8-heimdal": "7.5.0+dfsg-1", "libsl0-heimdal": "7.5.0+dfsg-1", "heimdal-clients-dbgsym": "7.5.0+dfsg-1", "heimdal-servers-dbgsym": "7.5.0+dfsg-1", "libkrb5-26-heimdal": "7.5.0+dfsg-1", "heimdal-docs": "7.5.0+dfsg-1", "libkrb5-26-heimdal-dbgsym": "7.5.0+dfsg-1", "libwind0-heimdal": "7.5.0+dfsg-1", "libroken18-heimdal": "7.5.0+dfsg-1", "libkafs0-heimdal": "7.5.0+dfsg-1", "libhcrypto4-heimdal-dbgsym": "7.5.0+dfsg-1", "libwind0-heimdal-dbgsym": "7.5.0+dfsg-1", "libheimntlm0-heimdal": "7.5.0+dfsg-1", "libroken18-heimdal-dbgsym": "7.5.0+dfsg-1", "libhx509-5-heimdal": "7.5.0+dfsg-1", "libkdc2-heimdal": "7.5.0+dfsg-1", "heimdal-multidev": "7.5.0+dfsg-1" } ] }