Bugzilla – Bug 1206730
VUL-0: CVE-2022-44640: libheimdal: Invalid free in ASN.1 codec
Last modified: 2023-01-31 14:34:10 UTC
CVE-2022-44640 Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Center (KDC). References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-44640 https://security-tracker.debian.org/tracker/DSA-5287-1 https://www.cve.org/CVERecord?id=CVE-2022-44640 https://github.com/heimdal/heimdal/security/advisories/GHSA-88pm-hfmq-7vv4 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=996586
Backports codestreams are affected: - openSUSE:Backports:SLE-15-SP3 - openSUSE:Backports:SLE-15-SP4
Done by enzokiel: - 15.3: https://build.opensuse.org/request/show/1044309 - 15.4: https://build.opensuse.org/request/show/1044311
released