UBUNTU-CVE-2019-12098
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-12098
UBUNTU-CVE-2019-12098
Summary:
Details: In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
References: https://ubuntu.com/security/CVE-2019-12098, http://www.h5l.org/pipermail/heimdal-announce/2019-May/000009.html, https://github.com/heimdal/heimdal/compare/3e58559...bbafe72, https://github.com/heimdal/heimdal/releases/tag/heimdal-7.6.0, https://ubuntu.com/security/notices/USN-5675-1, https://www.cve.org/CVERecord?id=CVE-2019-12098
Affected packages
Package
Name: heimdal
Purl: pkg:deb/ubuntu/[email protected]~git20131207+dfsg-1ubuntu1.2+esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
