Vulnerability Bulletins |
DSA-3912 heimdal - security update |
|
| Affected software | Debian |
|
Jeffrey Altman, Viktor Dukhovni, and Nicolas Williams reported thatHeimdal, an implementation of Kerberos 5 that aims to be compatible withMIT Kerberos, trusts metadata taken from the unauthenticated plaintext(Ticket), rather than the authenticated and encrypted KDC response. Aman-in-the-middle attacker can use this flaw to impersonate services tothe client. More info: https://www.debian.org/security/2017/dsa-3912 |
|






