CVE Vulnerabilities

CVE-2022-44640

Published: Dec 25, 2022 | Modified: Apr 15, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Center (KDC).

Affected Software

NameVendorStart VersionEnd Version
HeimdalHeimdal_project*7.7.1 (excluding)
HeimdalUbuntubionic*
HeimdalUbuntudevel*
HeimdalUbuntuesm-apps/jammy*
HeimdalUbuntuesm-apps/noble*
HeimdalUbuntuesm-infra-legacy/trusty*
HeimdalUbuntuesm-infra/bionic*
HeimdalUbuntuesm-infra/focal*
HeimdalUbuntuesm-infra/xenial*
HeimdalUbuntufocal*
HeimdalUbuntujammy*
HeimdalUbuntukinetic*
HeimdalUbuntulunar*
HeimdalUbuntumantic*
HeimdalUbuntunoble*
HeimdalUbuntuoracular*
HeimdalUbuntuplucky*
HeimdalUbuntuquesting*
HeimdalUbuntutrusty*
HeimdalUbuntutrusty/esm*
HeimdalUbuntuupstream*
HeimdalUbuntuxenial*
SambaUbuntutrusty*
SambaUbuntuupstream*
SambaUbuntuxenial*

References