UbuntuUpdates.org

Bugs fixes in "heimdal"

Origin Bug number Title Date fixed
Debian 1055316 heimdal: fails to build against glibc 2.38 2024-01-06
Launchpad 2036253 FTBFS: missing strl* symbols fail the build 2024-01-06
CVE CVE-2022-45142 gsskrb5: fix accidental logic inversions 2023-02-08
CVE CVE-2022-45142 gsskrb5: fix accidental logic inversions 2023-02-08
CVE CVE-2022-45142 gsskrb5: fix accidental logic inversions 2023-02-08
CVE CVE-2022-45142 gsskrb5: fix accidental logic inversions 2023-02-08
CVE CVE-2022-45142 gsskrb5: fix accidental logic inversions 2023-02-08
CVE CVE-2022-45142 gsskrb5: fix accidental logic inversions 2023-02-08
CVE CVE-2022-45142 gsskrb5: fix accidental logic inversions 2023-02-08
CVE CVE-2022-45142 gsskrb5: fix accidental logic inversions 2023-02-08
CVE CVE-2022-44640 Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Cen 2023-01-12
CVE CVE-2022-42898 PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, 2023-01-12
CVE CVE-2022-3437 Buffer overflow in Heimdal unwrap_des3() 2023-01-12
CVE CVE-2021-44758 Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzer 2023-01-12
CVE CVE-2022-44640 Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Cen 2023-01-12
CVE CVE-2022-42898 PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, 2023-01-12
CVE CVE-2022-3437 Buffer overflow in Heimdal unwrap_des3() 2023-01-12
CVE CVE-2021-44758 Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzer 2023-01-12
CVE CVE-2022-44640 Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Cen 2023-01-12
CVE CVE-2022-42898 PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, 2023-01-12



About   -   Send Feedback to @ubuntu_updates