openSUSE-SU-2023:0020-1

    Dashboard / Vulnerabilities / openSUSE-SU-2023:0020-1

    openSUSE-SU-2023:0020-1

    Published: 16 Jan 2023Last Modified: 4 Feb 2026

    Summary: Security update for libheimdal

    Details: This update for libheimdal fixes the following issues: Update to version 7.8.0 - CVE-2022-42898 PAC parse integer overflows - CVE-2022-3437 Overflows and non-constant time leaks in DES{,3} and arcfour - CVE-2022-41916 Fix Unicode normalization read of 1 bytes past end of array - CVE-2021-44758 A null pointer de-reference DoS in SPNEGO acceptors - CVE-2021-3671 A null pointer de-reference when handling missing sname in TGS-REQ - CVE-2022-44640 Heimdal KDC: invalid free in ASN.1 codec - CVE-2019-14870: Validate client attributes in protocol-transition

    Affected packages

    Package

    Name: libheimdal

    Purl: pkg:rpm/suse/libheimdal&distro=SUSE%20Package%20Hub%2015%20SP3

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -7.8.0-bp153.2.4.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    openSUSE-SU-2023:0020-1 | CVE-DB