Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in enc_part instead of the unencrypted version stored in ticket. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Heimdal | Heimdal_project | * | 7.4.0 (excluding) |
Heimdal | Ubuntu | trusty | * |
Heimdal | Ubuntu | vivid/ubuntu-core | * |
Heimdal | Ubuntu | xenial | * |
Heimdal | Ubuntu | yakkety | * |
Heimdal | Ubuntu | zesty | * |
Samba | Ubuntu | devel | * |
Samba | Ubuntu | trusty | * |
Samba | Ubuntu | xenial | * |
Samba | Ubuntu | yakkety | * |
Samba | Ubuntu | zesty | * |