Vulnerability Bulletins

DSA-3912 heimdal - security update

   
Affected software Debian
 
Jeffrey Altman, Viktor Dukhovni, and Nicolas Williams reported thatHeimdal, an implementation of Kerberos 5 that aims to be compatible withMIT Kerberos, trusts metadata taken from the unauthenticated plaintext(Ticket), rather than the authenticated and encrypted KDC response. Aman-in-the-middle attacker can use this flaw to impersonate services tothe client.

More info:

https://www.debian.org/security/2017/dsa-3912