In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Heimdal | Heimdal_project | * | 7.6.0 (excluding) |
Heimdal | Ubuntu | bionic | * |
Heimdal | Ubuntu | cosmic | * |
Heimdal | Ubuntu | disco | * |
Heimdal | Ubuntu | esm-infra/xenial | * |
Heimdal | Ubuntu | precise/esm | * |
Heimdal | Ubuntu | trusty | * |
Heimdal | Ubuntu | trusty/esm | * |
Heimdal | Ubuntu | upstream | * |
Heimdal | Ubuntu | xenial | * |