Do your applications use this vulnerable package?
Test your applications
Overview
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
References
CVSS Score
7.4
low severity
-
Attack VectorNetwork
-
Attack ComplexityHigh
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityNone
- CVE
- CVE-2019-12098
- CWE
- CWE-320
- Snyk ID
- SNYK-UBUNTU1804-HEIMDAL-346634
- Disclosed
- 15 May, 2019
- Published
- 15 May, 2019