Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_response value to send_accept.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Heimdal | Heimdal_project | * | 7.7.1 (excluding) |
Heimdal | Ubuntu | bionic | * |
Heimdal | Ubuntu | devel | * |
Heimdal | Ubuntu | esm-apps/jammy | * |
Heimdal | Ubuntu | esm-apps/noble | * |
Heimdal | Ubuntu | esm-infra/xenial | * |
Heimdal | Ubuntu | focal | * |
Heimdal | Ubuntu | jammy | * |
Heimdal | Ubuntu | kinetic | * |
Heimdal | Ubuntu | lunar | * |
Heimdal | Ubuntu | mantic | * |
Heimdal | Ubuntu | noble | * |
Heimdal | Ubuntu | oracular | * |
Heimdal | Ubuntu | trusty | * |
Heimdal | Ubuntu | trusty/esm | * |
Heimdal | Ubuntu | upstream | * |
Heimdal | Ubuntu | xenial | * |