USN-5849-1: Heimdal vulnerabilities
8 February 2023
Heimdal could be made to crash if it received specially crafted input.
Releases
Packages
- heimdal - Heimdal Kerberos Network Authentication Protocol
Details
Helmut Grohne discovered that Heimdal GSSAPI incorrectly handled logical
conditions that are related to memory management operations.
An attacker could possibly use this issue to cause a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04
Ubuntu 18.04
Ubuntu 16.04
-
libgssapi3-heimdal
-
1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4
Available with Ubuntu Pro
Ubuntu 14.04
-
libgssapi3-heimdal
-
1.6~git20131207+dfsg-1ubuntu1.2+esm4
Available with Ubuntu Pro
After a standard system update you need to restart any application
using Heimdal libraries to make all the necessary changes.