CVE Vulnerabilities

CVE-2017-6594

Improper Certificate Validation

Published: Aug 28, 2017 | Modified: Apr 20, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath policy protection mechanism by leveraging failure to add the previous hop realm to the transit path of issued tickets.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
HeimdalHeimdal_project*7.2.0 (including)
HeimdalUbuntuesm-infra-legacy/trusty*
HeimdalUbuntuesm-infra/xenial*
HeimdalUbuntuprecise*
HeimdalUbuntuprecise/esm*
HeimdalUbuntutrusty*
HeimdalUbuntutrusty/esm*
HeimdalUbuntuupstream*
HeimdalUbuntuvivid/stable-phone-overlay*
HeimdalUbuntuvivid/ubuntu-core*
HeimdalUbuntuxenial*
HeimdalUbuntuyakkety*
HeimdalUbuntuzesty*

Potential Mitigations

References