CVE Vulnerabilities

CVE-2017-6594

Improper Certificate Validation

Published: Aug 28, 2017 | Modified: Aug 12, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath policy protection mechanism by leveraging failure to add the previous hop realm to the transit path of issued tickets.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Heimdal Heimdal_project * 7.2.0 (including)
Heimdal Ubuntu esm-infra-legacy/trusty *
Heimdal Ubuntu esm-infra/xenial *
Heimdal Ubuntu precise *
Heimdal Ubuntu precise/esm *
Heimdal Ubuntu trusty *
Heimdal Ubuntu trusty/esm *
Heimdal Ubuntu upstream *
Heimdal Ubuntu vivid/stable-phone-overlay *
Heimdal Ubuntu vivid/ubuntu-core *
Heimdal Ubuntu xenial *
Heimdal Ubuntu yakkety *
Heimdal Ubuntu zesty *

Potential Mitigations

References