Univention Bugzilla – Full Text Bug Listing |
Summary: | Heimdal: KDC-REP issue (4.2) | ||
---|---|---|---|
Product: | UCS | Reporter: | Arvid Requate <requate> |
Component: | Security updates | Assignee: | Arvid Requate <requate> |
Status: | CLOSED FIXED | QA Contact: | Felix Botner <botner> |
Severity: | normal | ||
Priority: | P5 | CC: | hahn |
Version: | UCS 4.2 | Flags: | requate:
Patch_Available+
|
Target Milestone: | UCS 4.2-1-errata | ||
Hardware: | Other | ||
OS: | Linux | ||
URL: | https://www.orpheus-lyre.info/ | ||
See Also: | https://forge.univention.org/bugzilla/show_bug.cgi?id=44982 | ||
What kind of report is it?: | Security Issue | What type of bug is this?: | --- |
Who will be affected by this bug?: | --- | How will those affected feel about the bug?: | --- |
User Pain: | Enterprise Customer affected?: | ||
School Customer affected?: | ISV affected?: | ||
Waiting Support: | Flags outvoted (downgraded) after PO Review: | ||
Ticket number: | Bug group (optional): | Security | |
Max CVSS v3 score: | |||
Bug Depends on: | |||
Bug Blocks: | 44985, 45028 |
Heimdal rebuilt in errata4.2-1 with patch. Advisory: heimdal.yaml OK - patch OK - YAML OK - installation OK - kinit/ldapsearch -Y GSSAPI OK - univention-system-check d153aab1 Bug #44984 debmirror: Skip heimdal-1.6~rc2+dfsg-9+deb8u1 import |
Created attachment 9019 [details] 0300-CVE-2017-11103-Orpheus-Lyre-KDC-REP-service-name-val.quilt The following issue has been fixed in upstream Heimdal: * Orpheus' Lyre KDC-REP service name validation (mutual auth bypass) in embedded Heimdal (CVE-2017-11103)