UBUNTU-CVE-2019-12098

See a problem?
Source
https://ubuntu.com/security/notices/UBUNTU-CVE-2019-12098
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-12098.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2019-12098
Related
Published
2019-05-15T23:29:00Z
Modified
2019-05-15T23:29:00Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
  • 7.4 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5initcredsstep in lib/krb5/initcreds_pw.c.

References

Affected packages

Ubuntu:Pro:14.04:LTS / heimdal

Package

Name
heimdal
Purl
pkg:deb/ubuntu/heimdal@1.6~git20131207+dfsg-1ubuntu1.2+esm1?arch=src?distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6~git20131207+dfsg-1ubuntu1.2+esm1

Affected versions

1.*

1.6~git20120403+dfsg1-3ubuntu0.1
1.6~git20120403+dfsg1-3ubuntu0.2
1.6~git20131207+dfsg-1ubuntu1
1.6~git20131207+dfsg-1ubuntu1.1
1.6~git20131207+dfsg-1ubuntu1.2

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "libasn1-8-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-servers": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-servers-x-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libhx509-5-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libgssapi3-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libheimbase1-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-dbg": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libheimntlm0-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-kcm": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libheimbase1-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libotp0-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-multidev-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libotp0-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-servers-x": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libhcrypto4-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-dev": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkdc2-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-kdc": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-kcm-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libsl0-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libhdb9-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkadm5clnt7-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-kdc-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkadm5clnt7-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libasn1-8-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-clients": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libhdb9-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libgssapi3-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkafs0-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkadm5srv8-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkadm5srv8-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libsl0-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-clients-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-servers-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-clients-x": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-docs": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkrb5-26-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libwind0-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libroken18-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkafs0-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkrb5-26-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libhcrypto4-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libwind0-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libheimntlm0-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-dev-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libhx509-5-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libroken18-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-clients-x-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkdc2-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-multidev": "1.6~git20131207+dfsg-1ubuntu1.2+esm1"
        }
    ]
}

Ubuntu:Pro:16.04:LTS / heimdal

Package

Name
heimdal
Purl
pkg:deb/ubuntu/heimdal@1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1?arch=src?distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1

Affected versions

1.*

1.6~rc2+dfsg-10ubuntu1
1.7~git20150920+dfsg-4ubuntu1
1.7~git20150920+dfsg-4ubuntu1.16.04.1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "libasn1-8-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-servers": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libotp0-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libhx509-5-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libgssapi3-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libheimbase1-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-dbg": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libheimntlm0-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-kcm": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libheimbase1-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libotp0-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-multidev-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libhcrypto4-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libhdb9-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-dev": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkdc2-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-kdc": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-kcm-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libsl0-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkadm5clnt7-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-kdc-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkadm5clnt7-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libasn1-8-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-clients": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libhdb9-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libgssapi3-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkafs0-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkadm5srv8-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkadm5srv8-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libsl0-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-clients-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-servers-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkrb5-26-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-docs": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkrb5-26-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libwind0-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libroken18-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkafs0-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libhcrypto4-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libwind0-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libheimntlm0-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-dev-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libhx509-5-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libroken18-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkdc2-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-multidev": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1"
        }
    ]
}

Ubuntu:18.04:LTS / heimdal

Package

Name
heimdal
Purl
pkg:deb/ubuntu/heimdal@7.5.0+dfsg-1ubuntu0.1?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.5.0+dfsg-1ubuntu0.1

Affected versions

7.*

7.4.0.dfsg.1-2
7.5.0+dfsg-1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "libasn1-8-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libhdb9-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libhcrypto4-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libhx509-5-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libgssapi3-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libheimbase1-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libheimntlm0-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libotp0-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-kcm": "7.5.0+dfsg-1ubuntu0.1",
            "libheimbase1-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libotp0-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-multidev-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-servers": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-dev": "7.5.0+dfsg-1ubuntu0.1",
            "libkdc2-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-kcm-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-kdc": "7.5.0+dfsg-1ubuntu0.1",
            "libsl0-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libkadm5clnt7-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-kdc-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libkadm5clnt7-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libasn1-8-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-clients": "7.5.0+dfsg-1ubuntu0.1",
            "libhdb9-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libgssapi3-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libkafs0-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libkadm5srv8-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libkadm5srv8-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libsl0-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-clients-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-servers-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libkrb5-26-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-docs": "7.5.0+dfsg-1ubuntu0.1",
            "libkrb5-26-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libwind0-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libroken18-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libkafs0-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libhcrypto4-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libwind0-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libheimntlm0-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libroken18-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libhx509-5-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libkdc2-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-multidev": "7.5.0+dfsg-1ubuntu0.1"
        }
    ]
}

Ubuntu:20.04:LTS / heimdal

Package

Name
heimdal
Purl
pkg:deb/ubuntu/heimdal@7.5.0+dfsg-3build1?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.5.0+dfsg-3build1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "libasn1-8-heimdal-dbgsym": "7.5.0+dfsg-3build1",
            "libhdb9-heimdal-dbgsym": "7.5.0+dfsg-3build1",
            "libhcrypto4-heimdal": "7.5.0+dfsg-3build1",
            "libhx509-5-heimdal-dbgsym": "7.5.0+dfsg-3build1",
            "libgssapi3-heimdal-dbgsym": "7.5.0+dfsg-3build1",
            "libheimbase1-heimdal-dbgsym": "7.5.0+dfsg-3build1",
            "libheimntlm0-heimdal-dbgsym": "7.5.0+dfsg-3build1",
            "libotp0-heimdal": "7.5.0+dfsg-3build1",
            "heimdal-kcm": "7.5.0+dfsg-3build1",
            "libheimbase1-heimdal": "7.5.0+dfsg-3build1",
            "libotp0-heimdal-dbgsym": "7.5.0+dfsg-3build1",
            "heimdal-multidev-dbgsym": "7.5.0+dfsg-3build1",
            "heimdal-servers": "7.5.0+dfsg-3build1",
            "heimdal-dev": "7.5.0+dfsg-3build1",
            "libkdc2-heimdal-dbgsym": "7.5.0+dfsg-3build1",
            "heimdal-kcm-dbgsym": "7.5.0+dfsg-3build1",
            "heimdal-kdc": "7.5.0+dfsg-3build1",
            "libsl0-heimdal-dbgsym": "7.5.0+dfsg-3build1",
            "libkadm5clnt7-heimdal": "7.5.0+dfsg-3build1",
            "heimdal-kdc-dbgsym": "7.5.0+dfsg-3build1",
            "libkadm5clnt7-heimdal-dbgsym": "7.5.0+dfsg-3build1",
            "libasn1-8-heimdal": "7.5.0+dfsg-3build1",
            "heimdal-clients": "7.5.0+dfsg-3build1",
            "libhdb9-heimdal": "7.5.0+dfsg-3build1",
            "libgssapi3-heimdal": "7.5.0+dfsg-3build1",
            "libkafs0-heimdal-dbgsym": "7.5.0+dfsg-3build1",
            "libkadm5srv8-heimdal-dbgsym": "7.5.0+dfsg-3build1",
            "libkadm5srv8-heimdal": "7.5.0+dfsg-3build1",
            "libsl0-heimdal": "7.5.0+dfsg-3build1",
            "heimdal-clients-dbgsym": "7.5.0+dfsg-3build1",
            "heimdal-servers-dbgsym": "7.5.0+dfsg-3build1",
            "libkrb5-26-heimdal": "7.5.0+dfsg-3build1",
            "heimdal-docs": "7.5.0+dfsg-3build1",
            "libkrb5-26-heimdal-dbgsym": "7.5.0+dfsg-3build1",
            "libwind0-heimdal": "7.5.0+dfsg-3build1",
            "libroken18-heimdal": "7.5.0+dfsg-3build1",
            "libkafs0-heimdal": "7.5.0+dfsg-3build1",
            "libhcrypto4-heimdal-dbgsym": "7.5.0+dfsg-3build1",
            "libwind0-heimdal-dbgsym": "7.5.0+dfsg-3build1",
            "libheimntlm0-heimdal": "7.5.0+dfsg-3build1",
            "libroken18-heimdal-dbgsym": "7.5.0+dfsg-3build1",
            "libhx509-5-heimdal": "7.5.0+dfsg-3build1",
            "libkdc2-heimdal": "7.5.0+dfsg-3build1",
            "heimdal-multidev": "7.5.0+dfsg-3build1"
        }
    ]
}