CVE-2019-12098

NameCVE-2019-12098
DescriptionIn the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-4455-1
NVD severitymedium (attack range: remote)
Debian Bugs929064

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
heimdal (PTS)jessie (security), jessie1.6~rc2+dfsg-9+deb8u1vulnerable
stretch7.1.0+dfsg-13+deb9u2vulnerable
stretch (security)7.1.0+dfsg-13+deb9u3fixed
bullseye, sid, buster7.5.0+dfsg-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
heimdalsource(unstable)7.5.0+dfsg-3medium929064
heimdalsourcestretch7.1.0+dfsg-13+deb9u3mediumDSA-4455-1

Notes

[jessie] - heimdal <no-dsa> (Minor issue)
Fixed by: https://github.com/heimdal/heimdal/commit/2f7f3d9960aa6ea21358bdf3687cee5149aa35cf (7.6.0)
Introduced by: https://github.com/heimdal/heimdal/commit/a1ef548600c5bb51cf52a9a9ea12676506ede19f (1.4.0)

Search for package or bug name: Reporting problems