src
src copied to clipboard
CVE-2019-12098 (High) detected in heimdaleb87af0c2d189c25294c7daf483a47b03af80c2c
CVE-2019-12098 - High Severity Vulnerability
Vulnerable Library - heimdaleb87af0c2d189c25294c7daf483a47b03af80c2c
Heimdal
Library home page: https://github.com/heimdal/heimdal.git
Found in base branches: stable/3.2, master
Vulnerable Source Files (1)
/crypto/heimdal/lib/krb5/krb5_locl.h
Vulnerability Details
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
Publish Date: 2019-05-15
URL: CVE-2019-12098
CVSS 3 Score Details (7.4)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: https://gitlab.alpinelinux.org/alpine/aports/issues/10551
Release Date: 2019-05-15
Fix Resolution: 7.6.0
Step up your Open Source Security Game with Mend here