Buffer overflow in heimdal - CVE-2022-44640

 

Buffer overflow in heimdal - CVE-2022-44640

Published: November 16, 2022


Vulnerability identifier: #VU69364
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-44640
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in ASN.1 codec in Heimdal. The ASN.1 compiler generates code that allows specially crafted DER encodings of CHOICEs to invoke the wrong free function on the decoded structure upon decode error. This is known to impact the Heimdal KDC, leading to an invalid free() of an address partly or wholly under the control of the attacker. A remote attacker can execute arbitrary code on the system.



Affected software

heimdal
Debian Linux
Fedora
FreeBSD
Ubuntu
openEuler
EMC Integrated Data Protection Appliance
libhx509-5-heimdal (Ubuntu package)
libgssapi3-heimdal (Ubuntu package)
libkrb5-26-heimdal (Ubuntu package)
libasn1-8-heimdal (Ubuntu package)
libhdb9-heimdal (Ubuntu package)
samba-dc
libsmbclient
libwbclient-devel
samba-winbind-krb5-locator
samba-winbind-modules
libsmbclient-devel
samba-common
python3-samba-dc
samba-dc-provision
samba-krb5-printing
samba-debuginfo
samba-libs
samba-help
samba-client
samba-vfs-glusterfs
ctdb-tests
python3-samba-test
samba-pidl
samba-devel
samba-winbind
python3-samba
samba-winbind-clients
libwbclient
samba-common-tools
samba-test
samba-dc-bind-dlz
samba-debugsource
ctdb
samba
heimdal (Debian package)
heimdal
cflinuxfs3
Avamar Data Store Gen5A
Platform Automation Toolkit
iDRAC9
PowerScale OneFS

How to mitigate CVE-2022-44640

Install updates from vendor's website.

heimdal - update to 7.7.1
libhx509-5-heimdal (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.5.0+dfsg-1ubuntu0.3, 7.7.0+dfsg-1ubuntu1.3
libgssapi3-heimdal (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.5.0+dfsg-1ubuntu0.3, 7.7.0+dfsg-1ubuntu1.3
libkrb5-26-heimdal (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.5.0+dfsg-1ubuntu0.3, 7.7.0+dfsg-1ubuntu1.3
libasn1-8-heimdal (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.5.0+dfsg-1ubuntu0.3, 7.7.0+dfsg-1ubuntu1.3
libhdb9-heimdal (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.5.0+dfsg-1ubuntu0.3, 7.7.0+dfsg-1ubuntu1.3
cflinuxfs3 - update to 0.349.0
Avamar Data Store Gen5A - update to 2.18.1
Platform Automation Toolkit - addressed in versions 4.4.31, 5.0.24, 5.1.0
samba-dc - update to 4.11.12-23
libsmbclient - update to 4.11.12-23
libwbclient-devel - update to 4.11.12-23
samba-winbind-krb5-locator - update to 4.11.12-23
samba-winbind-modules - update to 4.11.12-23
libsmbclient-devel - update to 4.11.12-23
samba-common - update to 4.11.12-23
python3-samba-dc - update to 4.11.12-23
samba-dc-provision - update to 4.11.12-23
samba-krb5-printing - update to 4.11.12-23
samba-debuginfo - update to 4.11.12-23
samba-libs - update to 4.11.12-23
samba-help - update to 4.11.12-23
samba-client - update to 4.11.12-23
samba-vfs-glusterfs - update to 4.11.12-23
ctdb-tests - update to 4.11.12-23
python3-samba-test - update to 4.11.12-23
samba-pidl - update to 4.11.12-23
samba-devel - update to 4.11.12-23
samba-winbind - update to 4.11.12-23
python3-samba - update to 4.11.12-23
samba-winbind-clients - update to 4.11.12-23
libwbclient - update to 4.11.12-23
samba-common-tools - update to 4.11.12-23
samba-test - update to 4.11.12-23
samba-dc-bind-dlz - update to 4.11.12-23
samba-debugsource - update to 4.11.12-23
ctdb - update to 4.11.12-23
samba - update to 4.11.12-23
iDRAC9 - addressed in versions 6.10.30.20, 6.10.39.00
heimdal (Debian package) - update to 7.7.0+dfsg-2+deb11u2
heimdal - addressed in versions 7.7.1-1.el7, 7.7.1-1.el8, 7.7.1-1.fc35, 7.7.1-1.fc36, 7.7.1-1.fc37, 7.7.1-3.fc35, 7.7.1-3.fc36, 7.7.1-3.fc37
PowerScale OneFS - update to 11.7

External References

Related Security Bulletins