[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2019-12098Date: (C)2019-06-19   (M)2023-12-22


In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.4CVSS Score : 5.8
Exploit Score: 2.2Exploit Score: 8.6
Impact Score: 5.2Impact Score: 4.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: HIGHAccess Complexity: MEDIUM
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: NONE
Integrity: HIGH 
Availability: NONE 
  
Reference:
https://seclists.org/bugtraq/2019/Jun/1
DSA-4455
FEDORA-2019-2fa7d6405b
FEDORA-2019-f3046b6bfb
http://www.h5l.org/pipermail/heimdal-announce/2019-May/000009.html
https://github.com/heimdal/heimdal/commit/2f7f3d9960aa6ea21358bdf3687cee5149aa35cf
https://github.com/heimdal/heimdal/compare/3e58559...bbafe72
https://github.com/heimdal/heimdal/releases/tag/heimdal-7.6.0
openSUSE-SU-2019:1682
openSUSE-SU-2019:1688
openSUSE-SU-2019:1888

CPE    1
cpe:/o:debian:debian_linux:9.0
OVAL    5
oval:org.secpod.oval:def:86629
oval:org.secpod.oval:def:84887
oval:org.secpod.oval:def:1901981
oval:org.secpod.oval:def:603934
...

© SecPod Technologies