Out-of-bounds read in heimdal - CVE-2022-41916
Published: November 16, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition in Heimdal's PKI certificate validation library. A remote attacker can pass a specially crafted certificate to the affected application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.
The vulnerability affects KDC (via PKINIT), kinit (via PKINIT), as well as any third-party applications using Heimdal's libhx509.
Affected software
Debian Linux
Fedora
FreeBSD
Ubuntu
libwind0-heimdal (Ubuntu package)
heimdal (Debian package)
heimdal
Tanzu Greenplum for Kubernetes
Platform Automation Toolkit
VMware Tanzu Operations Manager
Isolation Segment
VMware Tanzu Application Service for VMs
How to mitigate CVE-2022-41916
libwind0-heimdal (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.5.0+dfsg-1ubuntu0.2, 7.7.0+dfsg-1ubuntu1.2
Tanzu Greenplum for Kubernetes - update to 2.0.0
VMware Tanzu Operations Manager - update to 2.10.52
Isolation Segment - addressed in versions 2.11.25, 2.12.15, 2.13.10, 3.0.7, 4.0.0
VMware Tanzu Application Service for VMs - addressed in versions 2.11.31, 2.12.20, 2.13.13, 3.0.7, 4.0.0
Platform Automation Toolkit - addressed in versions 4.4.30, 5.0.23, 5.1.0
heimdal (Debian package) - update to 7.7.0+dfsg-2+deb11u2
heimdal - addressed in versions 7.7.1-1.el7, 7.7.1-1.el8, 7.7.1-1.fc35, 7.7.1-1.fc36, 7.7.1-1.fc37, 7.7.1-3.fc35, 7.7.1-3.fc36, 7.7.1-3.fc37
External References
Related Security Bulletins
- Multiple vulnerabilities in Heimdal
- FreeBSD update for heimdal
- Debian update for heimdal
- Ubuntu update for heimdal
- VMware Tanzu products update for Heimdal
- Fedora 37 update for heimdal
- Fedora 36 update for heimdal
- Fedora 35 update for heimdal
- Fedora EPEL 8 update for heimdal
- Fedora EPEL 7 update for heimdal
- Fedora 37 update for heimdal
- Fedora 35 update for heimdal
- Fedora 36 update for heimdal