USN-5675-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-5675-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5675-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-5675-1
Related
Published
2022-10-13T18:39:02.324742Z
Modified
2022-10-13T18:39:02.324742Z
Summary
heimdal vulnerabilities
Details

Isaac Boukris and Andrew Bartlett discovered that Heimdal's KDC was not properly performing checksum algorithm verifications in the S4U2Self extension module. An attacker could possibly use this issue to perform a machine-in-the-middle attack and request S4U2Self tickets for any user known by the application. This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2018-16860)

It was discovered that Heimdal was not properly handling the verification of key exchanges when an anonymous PKINIT was being used. An attacker could possibly use this issue to perform a machine-in-the-middle attack and expose sensitive information. This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2019-12098)

Joseph Sutton discovered that Heimdal was not properly handling memory management operations when dealing with TGS-REQ tickets that were missing information. An attacker could possibly use this issue to cause a denial of service. (CVE-2021-3671)

Michał Kępień discovered that Heimdal was not properly handling logical conditions that related to memory management operations. An attacker could possibly use this issue to cause a denial of service. (CVE-2022-3116)

References

Affected packages

Ubuntu:Pro:14.04:LTS / heimdal

Package

Name
heimdal
Purl
pkg:deb/ubuntu/heimdal@1.6~git20131207+dfsg-1ubuntu1.2+esm1?arch=src?distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6~git20131207+dfsg-1ubuntu1.2+esm1

Affected versions

1.*

1.6~git20120403+dfsg1-3ubuntu0.1
1.6~git20120403+dfsg1-3ubuntu0.2
1.6~git20131207+dfsg-1ubuntu1
1.6~git20131207+dfsg-1ubuntu1.1
1.6~git20131207+dfsg-1ubuntu1.2

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "libasn1-8-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-servers": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-servers-x-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libhx509-5-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libgssapi3-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libheimbase1-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-dbg": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libheimntlm0-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-kcm": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libheimbase1-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libotp0-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-multidev-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libotp0-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-servers-x": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libhcrypto4-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-dev": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkdc2-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-kdc": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-kcm-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libsl0-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libhdb9-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkadm5clnt7-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-kdc-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkadm5clnt7-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libasn1-8-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-clients": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libhdb9-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libgssapi3-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkafs0-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkadm5srv8-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkadm5srv8-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libsl0-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-clients-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-servers-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-clients-x": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-docs": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkrb5-26-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libwind0-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libroken18-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkafs0-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkrb5-26-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libhcrypto4-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libwind0-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libheimntlm0-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-dev-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libhx509-5-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libroken18-heimdal-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-clients-x-dbgsym": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "libkdc2-heimdal": "1.6~git20131207+dfsg-1ubuntu1.2+esm1",
            "heimdal-multidev": "1.6~git20131207+dfsg-1ubuntu1.2+esm1"
        }
    ]
}

Ubuntu:Pro:16.04:LTS / heimdal

Package

Name
heimdal
Purl
pkg:deb/ubuntu/heimdal@1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1?arch=src?distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1

Affected versions

1.*

1.6~rc2+dfsg-10ubuntu1
1.7~git20150920+dfsg-4ubuntu1
1.7~git20150920+dfsg-4ubuntu1.16.04.1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "libasn1-8-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-servers": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libotp0-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libhx509-5-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libgssapi3-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libheimbase1-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-dbg": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libheimntlm0-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-kcm": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libheimbase1-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libotp0-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-multidev-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libhcrypto4-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libhdb9-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-dev": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkdc2-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-kdc": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-kcm-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libsl0-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkadm5clnt7-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-kdc-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkadm5clnt7-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libasn1-8-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-clients": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libhdb9-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libgssapi3-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkafs0-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkadm5srv8-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkadm5srv8-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libsl0-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-clients-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-servers-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkrb5-26-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-docs": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkrb5-26-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libwind0-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libroken18-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkafs0-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libhcrypto4-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libwind0-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libheimntlm0-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-dev-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libhx509-5-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libroken18-heimdal-dbgsym": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "libkdc2-heimdal": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1",
            "heimdal-multidev": "1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1"
        }
    ]
}

Ubuntu:18.04:LTS / heimdal

Package

Name
heimdal
Purl
pkg:deb/ubuntu/heimdal@7.5.0+dfsg-1ubuntu0.1?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.5.0+dfsg-1ubuntu0.1

Affected versions

7.*

7.4.0.dfsg.1-2
7.5.0+dfsg-1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "libasn1-8-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libhdb9-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libhcrypto4-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libhx509-5-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libgssapi3-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libheimbase1-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libheimntlm0-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libotp0-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-kcm": "7.5.0+dfsg-1ubuntu0.1",
            "libheimbase1-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libotp0-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-multidev-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-servers": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-dev": "7.5.0+dfsg-1ubuntu0.1",
            "libkdc2-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-kcm-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-kdc": "7.5.0+dfsg-1ubuntu0.1",
            "libsl0-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libkadm5clnt7-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-kdc-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libkadm5clnt7-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libasn1-8-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-clients": "7.5.0+dfsg-1ubuntu0.1",
            "libhdb9-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libgssapi3-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libkafs0-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libkadm5srv8-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libkadm5srv8-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libsl0-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-clients-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-servers-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libkrb5-26-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-docs": "7.5.0+dfsg-1ubuntu0.1",
            "libkrb5-26-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libwind0-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libroken18-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libkafs0-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libhcrypto4-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libwind0-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libheimntlm0-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libroken18-heimdal-dbgsym": "7.5.0+dfsg-1ubuntu0.1",
            "libhx509-5-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "libkdc2-heimdal": "7.5.0+dfsg-1ubuntu0.1",
            "heimdal-multidev": "7.5.0+dfsg-1ubuntu0.1"
        }
    ]
}

Ubuntu:20.04:LTS / heimdal

Package

Name
heimdal
Purl
pkg:deb/ubuntu/heimdal@7.7.0+dfsg-1ubuntu1.1?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.7.0+dfsg-1ubuntu1.1

Affected versions

7.*

7.5.0+dfsg-3build1
7.7.0+dfsg-1
7.7.0+dfsg-1ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "libasn1-8-heimdal-dbgsym": "7.7.0+dfsg-1ubuntu1.1",
            "libhdb9-heimdal-dbgsym": "7.7.0+dfsg-1ubuntu1.1",
            "libhcrypto4-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "libhx509-5-heimdal-dbgsym": "7.7.0+dfsg-1ubuntu1.1",
            "libgssapi3-heimdal-dbgsym": "7.7.0+dfsg-1ubuntu1.1",
            "libheimbase1-heimdal-dbgsym": "7.7.0+dfsg-1ubuntu1.1",
            "libheimntlm0-heimdal-dbgsym": "7.7.0+dfsg-1ubuntu1.1",
            "libotp0-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "heimdal-kcm": "7.7.0+dfsg-1ubuntu1.1",
            "libheimbase1-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "libotp0-heimdal-dbgsym": "7.7.0+dfsg-1ubuntu1.1",
            "heimdal-multidev-dbgsym": "7.7.0+dfsg-1ubuntu1.1",
            "heimdal-servers": "7.7.0+dfsg-1ubuntu1.1",
            "heimdal-dev": "7.7.0+dfsg-1ubuntu1.1",
            "libkdc2-heimdal-dbgsym": "7.7.0+dfsg-1ubuntu1.1",
            "heimdal-kcm-dbgsym": "7.7.0+dfsg-1ubuntu1.1",
            "heimdal-kdc": "7.7.0+dfsg-1ubuntu1.1",
            "libsl0-heimdal-dbgsym": "7.7.0+dfsg-1ubuntu1.1",
            "libkadm5clnt7-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "heimdal-kdc-dbgsym": "7.7.0+dfsg-1ubuntu1.1",
            "libkadm5clnt7-heimdal-dbgsym": "7.7.0+dfsg-1ubuntu1.1",
            "libasn1-8-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "heimdal-clients": "7.7.0+dfsg-1ubuntu1.1",
            "libhdb9-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "libgssapi3-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "libkafs0-heimdal-dbgsym": "7.7.0+dfsg-1ubuntu1.1",
            "libkadm5srv8-heimdal-dbgsym": "7.7.0+dfsg-1ubuntu1.1",
            "libkadm5srv8-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "libsl0-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "heimdal-clients-dbgsym": "7.7.0+dfsg-1ubuntu1.1",
            "heimdal-servers-dbgsym": "7.7.0+dfsg-1ubuntu1.1",
            "libkrb5-26-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "heimdal-docs": "7.7.0+dfsg-1ubuntu1.1",
            "libkrb5-26-heimdal-dbgsym": "7.7.0+dfsg-1ubuntu1.1",
            "libwind0-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "libroken18-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "libkafs0-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "libhcrypto4-heimdal-dbgsym": "7.7.0+dfsg-1ubuntu1.1",
            "libwind0-heimdal-dbgsym": "7.7.0+dfsg-1ubuntu1.1",
            "libheimntlm0-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "libroken18-heimdal-dbgsym": "7.7.0+dfsg-1ubuntu1.1",
            "libhx509-5-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "libkdc2-heimdal": "7.7.0+dfsg-1ubuntu1.1",
            "heimdal-multidev": "7.7.0+dfsg-1ubuntu1.1"
        }
    ]
}