Error Handling in heimdal - CVE-2022-45142

 

Error Handling in heimdal - CVE-2022-45142

Published: February 8, 2023


Vulnerability identifier: #VU72057
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-45142
CWE-ID: CWE-388
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform a denial of service (DoS) attack.

The vulnerability exists due to a logic issue in Heimdal GSSAPI related to patch for vulnerability #VU68701 (CVE-2022-3437). A remote user can perform a denial of service (DoS) attack.


Affected software

heimdal
Debian Linux
Ubuntu
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
cflinuxfs3
Platform Automation Toolkit
Dell PowerProtect Cyber Recovery
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
libgssapi3-heimdal (Ubuntu package)
heimdal (Debian package)
IBM CICS TX Advanced

How to mitigate CVE-2022-45142

Install updates from vendor's website.

Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
libgssapi3-heimdal (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.5.0+dfsg-1ubuntu0.4, 7.7.0+dfsg-1ubuntu1.4
cflinuxfs3 - update to 0.351.0
Platform Automation Toolkit - addressed in versions 4.4.31, 5.0.24, 5.1.0
heimdal (Debian package) - update to 7.7.0+dfsg-2+deb11u3
IBM CICS TX Advanced - update to 10.1.0.0 ifix16
Dell PowerProtect Cyber Recovery - update to 19.14.0.1

External References

Related Security Bulletins