Debian Security Update DSA-5344 heimdal - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,952
Reaction score
80
Credits
-1,257
Helmut Grohne discovered a flaw in Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos. The backports of fixes for CVE-2022-3437 accidentally inverted important memory comparisons in the arcfour-hmac-md5 and rc4-hmac integrity check handlers for gssapi, resulting in incorrect validation of message integrity codes.

Continue reading...
 


Follow Linux.org

Members online


Top