Bug 1205667 - (CVE-2021-44758) VUL-0: CVE-2021-44758: libheimdal: multiple fixes
VUL-0: CVE-2021-44758: libheimdal: multiple fixes
Status: NEW
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.4
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Dominique Leuenberger
Security Team bot
Depends on:
  Show dependency treegraph
Reported: 2022-11-23 07:14 UTC by Alexander Bergmann
Modified: 2023-03-14 04:42 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2022-11-23 07:14:07 UTC
openSUSE:Backports and openSUSE:Factory only.


Several vulnerabilities were discovered in Heimdal, an implementation of
Kerberos 5 that aims to be compatible with MIT Kerberos.

Joseph Sutton discovered that the Heimdal KDC does not validate that
    the server name in the TGS-REQ is present before dereferencing,
    which may result in denial of service.
It was discovered that Heimdal is prone to a NULL dereference in
    acceptors where an initial SPNEGO token that has no acceptable
    mechanisms, which may result in denial of service for a server
    application that uses SPNEGO.
Several buffer overflow flaws and non-constant time leaks were
    discovered when using 1DES, 3DES or RC4 (arcfour).
An out-of-bounds memory access was discovered when Heimdal
    normalizes Unicode, which may result in denial of service.
It was discovered that integer overflows in PAC parsing may result
    in denial of service for Heimdal KDCs or possibly Heimdal servers.
It was discovered that the Heimdal's ASN.1 compiler generates code
    that allows specially crafted DER encodings to invoke an invalid
    free on the decoded structure upon decode error, which may result in
    remote code execution in the Heimdal KDC.

For the stable distribution (bullseye), these problems have been fixed in
version 7.7.0+dfsg-2+deb11u2.
We recommend that you upgrade your heimdal packages.
For the detailed security status of heimdal please refer to its security
tracker page at:

Comment 1 Andreas Stieger 2022-11-23 18:55:30 UTC
"libheimdal" in openSUSE. 
Fixed in 7.8.0
See https://github.com/heimdal/heimdal/releases/tag/heimdal-7.8.0

maintainer is not in bugzilla