Source: heimdal
Version: 7.5.0+dfsg-2.1
Severity: important
Tags: security upstream
Control: found -1 7.1.0+dfsg-13+deb9u2
Control: found -1 7.1.0+dfsg-13

Hi,

The following vulnerability was published for heimdal.

CVE-2019-12098[0]:
| In the client side of Heimdal before 7.6.0, failure to verify
| anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle
| attack. This issue is in krb5_init_creds_step in
| lib/krb5/init_creds_pw.c.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-12098
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12098
[1] http://www.h5l.org/pipermail/heimdal-announce/2019-May/000009.html
[2] 
https://github.com/heimdal/heimdal/commit/2f7f3d9960aa6ea21358bdf3687cee5149aa35cf

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to